Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GoogleUpdater.exe' = '%ALLUSERSPROFILE%\Application Data\WinDir64\test.exe'
- '' (downloaded from the Internet)
- %ALLUSERSPROFILE%\Application Data\WinDir64\test.exe
- %ALLUSERSPROFILE%\Application Data\WinDir64\test.exe
- 'up###e.h1n.ru':80
- http://up###e.h1n.ru/test.exe
- DNS ASK up###e.h1n.ru
- '%ALLUSERSPROFILE%\Application Data\WinDir64\test.exe'