Technical Information
- %WINDIR%\syswow64\cttunesvr.exe
- 'zk.##168.live':80
- http://8.###.63.120/index.php/inface/Heart/getConfigDyn?m_###########################################
- DNS ASK zk.##168.live
- '255.255.255.255':23779
- '255.255.255.255':23881
- '<LOCALNET>.29.60':62055
- '<LOCALNET>.29.60':55025
- '<LOCALNET>.29.60':55026
- '<LOCALNET>.29.60':55027
- '<LOCALNET>.29.60':55028
- '<LOCALNET>.29.60':55029
- '<SYSTEM32>\svchost.exe' -k LocalServiceNetwork -p
- '%WINDIR%\syswow64\cttunesvr.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "%WINDIR%\syswow64\cttunesvr.exe"