Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Win624svc' = '<Full path to file>'
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 1 /tn "Dec%USERNAME%" /tr "<Full path to file>"
- '<SYSTEM32>\schtasks.exe' /Create /TN "GOVCPI\GOVCPI" /XML "%APPDATA%\GOVCPI\afffff.xml"
- %APPDATA%\GOVCPI\afffff.xml
- %APPDATA%\GOVCPI\GOVCPI.exe
- %APPDATA%\GOVCPI\afffff.xml
- 'ne###.dyndns.ws':1928
- 'an###nter.pw':1928
- 'ip##pi.com':80
- 'wp#d':80
- '74.##5.232.51':80
- http://ip##pi.com/line/
- http://clients3.google.com/generate_204 via 74.##5.232.51
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK ne###.dyndns.ws
- DNS ASK an###nter.pw
- DNS ASK ip##pi.com
- DNS ASK wp#d
- DNS ASK clients3.google.com