Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Update' = '%ProgramFiles(x86)%\vceefe.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Update' = '%ProgramFiles(x86)%\vceefe.exe'
- %ProgramFiles(x86)%\vceefe.exe
- %TEMP%\tmp2ce0.tmp
- %TEMP%\tmp1b79.tmp
- %TEMP%\tmp2a1.tmp
- %TEMP%\tmpf070.tmp
- %TEMP%\tmpd8a1.tmp
- %TEMP%\tmpd218.tmp
- %TEMP%\tmp3c32.tmp
- %TEMP%\tmpc42d.tmp
- %TEMP%\tmp8f4f.tmp
- %TEMP%\tmp7b78.tmp
- %TEMP%\tmp731b.tmp
- %TEMP%\tmp3ad3.tmp
- %APPDATA%\36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee\run.dat
- %APPDATA%\data.bin
- %TEMP%\tmpa903.tmp
- %TEMP%\tmp69fa.tmp
- 'be#####45.duckdns.org':4001
- DNS ASK de#####5.duckdns.org
- DNS ASK be#####45.duckdns.org
- '%ProgramFiles(x86)%\vceefe.exe'
- '%ProgramFiles(x86)%\vceefe.exe' ' (with hidden window)