Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\E33067FA.lnk
- %ALLUSERSPROFILE%\Application Data\<File name>.dll
- %ALLUSERSPROFILE%\Application Data\<File name>.dllx.bat
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\index[1].php
- %ALLUSERSPROFILE%\Application Data\7E4CC913\DE90F875
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\index[1].php
- <Full path to file>
- %ALLUSERSPROFILE%\Application Data\7E4CC913\DE90F875
- %ALLUSERSPROFILE%\Application Data\7E4CC913\DE90F875
- 'localhost':1036
- '20#.#48.86.218':80
- http://20#.#48.86.218/index.php?m=############################################################################################
- '<SYSTEM32>\rundll32.exe' %ALLUSERSPROFILE%\Application Data\<File name>.dll,#1
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\Application Data\<File name>.dllx.bat