Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'tu2mgtpk' = '%APPDATA%\x2mb1m3.exe'
- x2mb1m3.exe
- %APPDATA%\x2mb1m3.exe
- 'mk###i4kdsz.com':80
- 'ow###rasuek.com':80
- http://mk###i4kdsz.com/778/242.html
- http://ow###rasuek.com/480/352.html
- DNS ASK ko##od.net
- DNS ASK mk###i4kdsz.com
- DNS ASK ow###rasuek.com
- '%APPDATA%\x2mb1m3.exe'