Technical Information
- [HKCU\software\microsoft\windows\currentversion\run] '<File name>' = 'WScript.exe //B "%APPDATA%\<File name>.js"'
- [HKLM\software\microsoft\windows\currentversion\run] '<File name>' = 'WScript.exe //B "%APPDATA%\<File name>.js"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.js
- <Drive name for removable media>:\<File name>.js
- %APPDATA%\<File name>.js
- <Drive name for removable media>:\<File name>.js
- 'ip##pi.com':80
- 'my##.#nsomatic.com':80
- 'pa###bin.com':443
- 'pk#.goog':80
- http://ip##pi.com/json/
- http://my##.#nsomatic.com/
- http://pk#.goog/gsr1/gsr1.crt
- 'pa###bin.com':443
- DNS ASK ip##pi.com
- DNS ASK my##.#nsomatic.com
- DNS ASK pa###bin.com
- DNS ASK pk#.goog
- DNS ASK bb##.live