Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'win32' = '%APPDATA%\sys32\sysinfo.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'win32' = '\sys32\sysinfo.exe'
- '%TEMP%\file196213\file196213.exe'
- '%APPDATA%\file196213.exe'
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 1000
- '<SYSTEM32>\taskmgr.exe'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 600
- '<SYSTEM32>\cmd.exe' /C ping 1.1.1.1 -n 1 -w 1000 > Nul & Del "%APPDATA%\file196213.exe"
- %APPDATA%\Imminent\Logs\22-11-2017
- %APPDATA%\sys32\sysinfo.exe
- %APPDATA%\Imminent\Path.dat
- %APPDATA%\Imminent\Monitoring\network.dat
- %APPDATA%\Imminent\Monitoring\system.dat
- %APPDATA%\file264908.exe
- %APPDATA%\file196213.exe
- %TEMP%\dw.log
- C:\sys32\sysinfo.exe
- %TEMP%\24481.dmp
- %TEMP%\file196213\file196213.exe
- %APPDATA%\file196213.exe
- 'tt#####3337.zapto.org':1604
- DNS ASK tt#####3337.zapto.org
- ClassName: '' WindowName: 'Windows Task Manager'