Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'X257549AV92BG' = '%APPDATA%\UJL4W87J7.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'X257549AV92BG' = '%APPDATA%\UJL4W87J7.exe'
- %TEMP%\ujl4w87j7.exe.jpg
- from <Full path to virus> to %APPDATA%\UJL4W87J7.exe
- 'ob####rk4zxc.com':80
- ob####rk4zxc.com/bot/alive.php?ke##################################################################################
- DNS ASK id###0rkjkl.com
- DNS ASK hj####4rds8fg.com
- DNS ASK ob####rk4zxc.com
- '<Private IP address>':1035
- ClassName: 'Indicator' WindowName: ''