Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\UserTools.exe' = '%TEMP%\UserTools.exe:*:Enabled:UserTools.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\UserTools.exe" "UserTools.exe" ENABLE
- %TEMP%\spc_player.dll
- %TEMP%\UserTools.exe
- %TEMP%\System.exe
- %TEMP%\amtemu.v0.9.2-painter.exe
- %TEMP%\Drivers.exe
- 'ka####.selfip.net':49123
- DNS ASK ka####.selfip.net
- '%TEMP%\System.exe'
- '%TEMP%\UserTools.exe'
- '%TEMP%\amtemu.v0.9.2-painter.exe'
- '%TEMP%\Drivers.exe'
- '<SYSTEM32>\cmd.exe' /k powershell REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /f /v EnableLUA /t REG_SZ /d %TEMP%\System.exe