Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\updatee.exe
- '%TEMP%\updatee.exe'
- '%ProgramFiles%\Windows NT\Accessories\wordpad.exe' "%TEMP%\ksa.doc"
- '<SYSTEM32>\cmd.exe' /c %TEMP%\ksa.doc
- %TEMP%\updatee.exe
- %TEMP%\ms4413.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\ksa.doc
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- 'mo###ffer.life':80
- 'my####rnalip.com':80
- http://my####rnalip.com/raw
- http://mo###ffer.life/
- DNS ASK mo###ffer.life
- DNS ASK my####rnalip.com
- ClassName: 'WordPadClass' WindowName: ''