Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ShinoBOT' = '"%HOMEPATH%\ShinoBOT.exe"'
- [<HKLM>\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable
- '%WINDIR%\syswow64\net.exe' stop wuauserv
- %HOMEPATH%\shinobot.exe
- DNS ASK sh####ot.mooo.com
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop wuauserv' (with hidden window)
- '%WINDIR%\syswow64\net1.exe' stop wuauserv