Technical Information
- %TEMP%\ukiryfs3
- %TEMP%\ukiryfs3.dll
- http://he####errick.com/g76dbf?dH###############
- http://od##ium.com/g76dbf?dH###############
- DNS ASK be#####giftsuk.co.uk
- DNS ASK he####errick.com
- DNS ASK od##ium.com
- '<SYSTEM32>\rundll32.exe' %LOCALAPPDATA%\Temp/UkIRYFS3.dll,qwerty' (with hidden window)
- '<SYSTEM32>\rundll32.exe' %LOCALAPPDATA%\Temp/UkIRYFS3.dll,qwerty