Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%APPDATA%\0p3Yv8fGy3NV7n63\XJ5KfLPxIdjX.exe",explorer.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- %APPDATA%\0p3Yv8fGy3NV7n63\XJ5KfLPxIdjX.exe
- %APPDATA%\0p3Yv8fGy3NV7n63\XJ5KfLPxIdjX.exe
- 'sm####9.ddns.net':3317
- 'ja####p79.ddns.net':3317
- 'go####79.ddns.net':3317
- 'wh####79.ddns.net':3317
- 'ch####e79.ddns.net':3317
- 'wi#####1979.ddns.net':3317
- 'bo####g79.ddns.net':3317
- 'en####79.ddns.net':3317
- 'ma####os79.ddns.net':3317
- DNS ASK sm####9.ddns.net
- DNS ASK ja####p79.ddns.net
- DNS ASK go####79.ddns.net
- DNS ASK wh####79.ddns.net
- DNS ASK ch####e79.ddns.net
- DNS ASK wi#####1979.ddns.net
- DNS ASK bo####g79.ddns.net
- DNS ASK en####79.ddns.net
- DNS ASK ma####os79.ddns.net