Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ZS' = '%APPDATA%\svchost.exe'
- '%APPDATA%\svchost.exe'
- '%APPDATA%\svchost.exe'
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="ZS" program="%APPDATA%\svchost.exe" dir=Out action=allow
- svchost.exe
- %APPDATA%\sqlite3.dll
- %APPDATA%\bs.dll
- %APPDATA%\zs.dll
- %APPDATA%\svchost.exe
- %APPDATA%\svchost.exe:Zone.Identifier
- '17#.#7.170.211':80
- http://17#.#7.170.211/panel/lib/bs.dll.c
- http://17#.#7.170.211/panel/lib/sql.dll.c
- http://17#.#7.170.211/panel/lib/zs.dll.c