Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'aabningsm' = '%HOMEPATH%\creirgistreac\piezoch.vbs'
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- piezoch.exe
- %HOMEPATH%\ethxol.exe
- %HOMEPATH%\creirgistreac\piezoch.exe
- %HOMEPATH%\creirgistreac\piezoch.vbs
- '87.##1.92.171':6698
- 'yu######hgrf.duckdns.org':2404
- http://ic#######xxx10314522289466.com/Ethxol.exe
- http://www.ar####astudios.us/Build_encrypted_2F77DB0.bin
- http://www.ar####astudios.us/remcos_agent_encrypted_598F560.bin
- DNS ASK ic#######xxx10314522289466.com
- DNS ASK ar####astudios.us
- DNS ASK yu######hgrf.duckdns.org
- '%HOMEPATH%\ethxol.exe'
- '%HOMEPATH%\creirgistreac\piezoch.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe' ' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'