Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'HHMTPLRXV' = '%ProgramFiles(x86)%\Dnnupd\systrayedg4.exe'
- '' (downloaded from the Internet)
- '%APPDATA%\vbc.exe'
- %WINDIR%\explorer.exe
- iexplore.exe
- %APPDATA%\vbc.exe
- %APPDATA%\n1opbrde\n1ologri.ini
- %APPDATA%\vbc.exe
- http://sm############tionlifesecurecenstdy3pls.duckdns.org/smldoc/regasm.exe
- http://www.la####namall.com/uts2/?8p#############################################################################################
- DNS ASK sm############tionlifesecurecenstdy3pls.duckdns.org
- DNS ASK ti###hon.com
- DNS ASK la####namall.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%APPDATA%\vbc.exe"