Technical Information
- '%TEMP%\cttunesvr.exe' /S /adv 1677
- '%TEMP%\cttunesvr.exe' (downloaded from the Internet)
- %TEMP%\win05.xml
- %TEMP%\cttunesvr.exe
- %TEMP%\win14.scr
- %TEMP%\win42.sys
- %TEMP%\win04.bmp
- %TEMP%\nst2.tmp\System.dll
- %TEMP%\nst2.tmp\inetc.dll
- %TEMP%\nst2.tmp\blowfish.dll
- 'sy##o.gdn':80
- '10#.#72.3.178':545
- http://sy##o.gdn/tc/geoip.php
- DNS ASK sy##o.gdn