Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'UserInit' = 'userinit.exe,%WINDIR%\apocalyps32.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'apocalyps32' = '%WINDIR%\apocalyps32.exe'
- %WINDIR%\explorer.exe
- %HOMEPATH%\desktop\split.avi
- %TEMP%\unpacked.exe
- %WINDIR%\apocalyps32.exe
- %WINDIR%\ap0calypse_4407f1b7\serverlogs\user\13-03-2020
- 'localhost':1453
- DNS ASK wa####n.no-ip.biz
- '%TEMP%\unpacked.exe'
- '%WINDIR%\apocalyps32.exe'
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe'