Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'JavaUpdat.exe' = '%APPDATA%\Oracle Corporation/Java/Updates\JavaUpdat.exe.exe'
- %APPDATA%\<File name>\<File name>.exe
- %APPDATA%\Oracle Corporation\Java\Updates\JavaUpdat.exe.exe
- C:\Documents
- %APPDATA%\%USERNAME%.txt
- <Full path to file>
- %APPDATA%\<File name>\<File name>.exe
- %APPDATA%\Oracle Corporation\Java\Updates\JavaUpdat.exe.exe
- %APPDATA%\Oracle Corporation\Java\Updates\JavaUpdat.exe.exe
- 'wp#d':80
- 'fr###eoip.net':80
- 'Pe#####tiontes.mooo.com':1215
- http://11#.#11.111.1/wpad.dat via wp#d
- http://fr###eoip.net/json/
- DNS ASK wp#d
- DNS ASK fr###eoip.net
- DNS ASK Pe#####tiontes.mooo.com
- '%APPDATA%\<File name>\<File name>.exe'
- '<SYSTEM32>\cmd.exe' /C ping 1.1.1.1 -n 1 -w 1000 > Nul & Del "<Full path to file>"
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 1000