Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WinApp' = '%APPDATA%\Windows\WinApp.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Update' = '<SYSTEM32>\helpar windos\winapp.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Update' = '<SYSTEM32>\helpar windos\winapp.exe'
- User Account Control (UAC)
- '<SYSTEM32>\helpar windos\winapp.exe'
- %APPDATA%\Imminent\Logs\02-12-2017
- %APPDATA%\Windows\WinApp.exe
- <SYSTEM32>\helpar windos\winapp.exe
- 'cr###.viewdns.net':9000
- DNS ASK cr###.viewdns.net