Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, rundll32 %TEMP%\d3dx11_19.dll Call_WinLoacal_LPE'
- '%ALLUSERSPROFILE%\Application Data\bitcoin_bot.exe'
- '<SYSTEM32>\rundll32.exe' "%TEMP%\d3dx11_19.dll",Call_WinLoacal_LPE
- %ALLUSERSPROFILE%\Application Data\bitcoin_bot.exe
- %TEMP%\d3dx11_19.dll
- from %TEMP%\d3dx11_19.dll to %TEMP%\d3dx11_19.dll
- 'go###sta.top':80
- http://go###sta.top/includes/tasks.php
- DNS ASK go###sta.top