Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'e83ce4cb8d53d3d116d120d7a31d28c9' = '"%TEMP%\Client.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'e83ce4cb8d53d3d116d120d7a31d28c9' = '"%TEMP%\Client.exe" ..'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\Client.exe" "Client.exe" ENABLE
- %TEMP%\client.exe
- '<LOCALNET>.219.102':1
- 'st###s.o-r.kr':1
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK cd#.##scordapp.com
- DNS ASK microsoft.com
- DNS ASK st###s.o-r.kr
- '%TEMP%\client.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\Client.exe" "Client.exe" ENABLE' (with hidden window)