Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'jootete' = '%HOMEPATH%\Start Menu\Programs\pooMOON.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'jootete' = '%HOMEPATH%\Start Menu\Programs\pooMOON.exe'
- pooMOON.exe
- %HOMEPATH%\Start Menu\Programs\pooMOON.exe:ZONE.identifier
- %HOMEPATH%\Start Menu\Programs\.Identifier
- <Full path to file>:ZONE.identifier
- %HOMEPATH%\Start Menu\Programs\pooMOON.exe
- %HOMEPATH%\Start Menu\Programs\.Identifier
- 'we#####ou1.no-ip.biz':6063
- '18#.17.1.97':6063
- DNS ASK we#####ou1.no-ip.biz
- '%HOMEPATH%\Start Menu\Programs\pooMOON.exe'
- '<SYSTEM32>\cmd.exe' /c echo [zoneTransfer]ZoneID = 2 > "%HOMEPATH%\Start Menu\Programs\pooMOON.exe":ZONE.identifier & exit
- '<SYSTEM32>\cmd.exe' /c echo [zoneTransfer]ZoneID = 2 > "<Full path to file>":ZONE.identifier & exit