Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '1c1ca01cd24f4704468e50b601bc2efb' = '"%ALLUSERSPROFILE%\host.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '1c1ca01cd24f4704468e50b601bc2efb' = '"%ALLUSERSPROFILE%\host.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\1c1ca01cd24f4704468e50b601bc2efb.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%ALLUSERSPROFILE%\host.exe" "host.exe" ENABLE
- %TEMP%\ducsetup_v4_1_1.exe
- %ALLUSERSPROFILE%\host.exe
- 'ma######ith.publicvm.com':5552
- 'pa###bin.com':443
- DNS ASK pa###bin.com
- DNS ASK ma######ith.publicvm.com
- '%TEMP%\ducsetup_v4_1_1.exe'
- '%ALLUSERSPROFILE%\host.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%ALLUSERSPROFILE%\host.exe" "host.exe" ENABLE' (with hidden window)