Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MOcQc' = '%LOCALAPPDATA%\MOcQca\MOcQcaNGz.hta'
- %WINDIR%\microsoft.net\framework\v2.0.50727\installutil.exe
- %LOCALAPPDATA%\mocqca\mocqc.exe
- %LOCALAPPDATA%\mocqca\mocqc.vbs
- %LOCALAPPDATA%\mocqca\mocqcangz.hta
- %APPDATA%\36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee\run.dat
- '18#.#65.153.129':5421
- '%WINDIR%\microsoft.net\framework\v2.0.50727\installutil.exe'