Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'LFSRb' = '%APPDATA%\LFSRb\LFSRb.exe'
- '' (downloaded from the Internet)
- '%APPDATA%\davinci2648.scr'
- davinci2648.scr
- %APPDATA%\davinci2648.scr
- %APPDATA%\lfsrb\lfsrb.exe
- '19#.#39.147.103':80
- http://19#.#39.147.103/base/36CFBC8AC1A486B8BF4A7993A6962894.html
- http://19#.#39.147.103/base/BE9E07DA0BBF8C6680F94B3B8384CE96.html
- http://19#.#39.147.103/base/124F9A63ED84EEF7221014DB6DFD4AD5.html
- DNS ASK tu###inblog.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding