Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ShinoBOT' = '"%HOMEPATH%\ShinoBOT.exe"'
- [<HKLM>\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable
- '%WINDIR%\syswow64\net.exe' stop wuauserv
- %TEMP%\nsa_certificate_extension_rfc7169.txt
- %TEMP%\~tmpcf9f09bf.tmp
- %TEMP%\kb79590579.exe
- %HOMEPATH%\shinobot.exe
- http://sh####al.mooo.com/files/938df3e64ba6d5de_53DA90B3img.jpg
- DNS ASK sh####al.mooo.com
- DNS ASK sh####ot.mooo.com
- '%TEMP%\kb79590579.exe'
- '%TEMP%\kb79590579.exe' ' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop wuauserv' (with hidden window)
- '%WINDIR%\syswow64\notepad.exe' %TEMP%\NSA_Certificate_Extension_RFC7169.txt
- '%WINDIR%\syswow64\net1.exe' stop wuauserv