Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Sidio] 'ImagePath' = '<SYSTEM32>\IEtask.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Sidio] 'Start' = '00000002'
- C:\6524.vbs
- C:\6524.vbs
- from <SYSTEM32>\IEtask.exe to <SYSTEM32>\IEtask.exe
- from <Full path to file> to <SYSTEM32>\IEtask.exe
- 'ro####hn.eatuo.com':80
- DNS ASK ro####hn.eatuo.com
- '<SYSTEM32>\wscript.exe' "C:\6524.vbs"
- '<SYSTEM32>\IEtask.exe'