Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RFLDEOEEE' = '%LOCALAPPDATA%\RFLDEOEEE\RFLDEOEEEKUO.vbs'
- <SYSTEM32>\regsvr32.exe
- %TEMP%\sxy.bmp
- %TEMP%\sxylsr.exe
- %TEMP%\sxy.txt
- %HOMEPATH%\contacts\rfldeoeeeseo.exe
- %HOMEPATH%\desktop_a\rfldeoeee.bmp
- %LOCALAPPDATA%\rfldeoeee\rfldeoeeenko.bat
- %LOCALAPPDATA%\rfldeoeee\rfldeoeeekuo.vbs
- %APPDATA%\kkdkd\logs.dat
- %TEMP%\sxy.txt
- '17#.#24.140.144':2030
- '%TEMP%\sxylsr.exe'
- '%TEMP%\sxylsr.exe' ' (with hidden window)
- '<SYSTEM32>\regsvr32.exe'