Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\catqceo.url
- %ProgramFiles(x86)%\gihut\zbcx.exe
- C:\users\public\catqceo\catqceo.exe
- C:\users\public\catqceo\run.vbs
- C:\users\public\catqceo\temp.vbs
- %ProgramFiles(x86)%\gihut\zbcx.exe
- 'localhost':1
- DNS ASK dr###15.kro.kr
- ClassName: 'EDIT' WindowName: ''
- '%ProgramFiles(x86)%\gihut\zbcx.exe'
- '<SYSTEM32>\cscript.exe' C:\Users\Public\CATQCEO\temp.vbs