Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'My App' = '%APPDATA%\ggiogq.exe'
- hidden files
- file extensions
- ggiogq.exe
- %APPDATA%\ggiogq.exe
- %APPDATA%\ggiogq.exe
- '23#.#40.161.147':7410
- '2.###.148.157':7410
- 'vk###.kro.kr':7410
- '61.##.97.164':7410
- '24#.#37.174.170':7410
- '50.##8.123.177':7410
- '23#.#8.71.183':7410
- '40.##3.148.190':7410
- '22#.#4.97.196':7410
- '29.##1.46.203':7410
- '21#.#2.123.209':7410
- DNS ASK vk###.kro.kr
- '<Full path to file>'
- '%APPDATA%\ggiogq.exe'
- '<SYSTEM32>\reg.exe' ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "My App" /t REG_SZ /F /D "%APPDATA%\ggiogq.exe"