Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] '2600' = '%ALLUSERSPROFILE%\Local Settings\Temp\0a3afffe.com'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\svchost.exe
- %ALLUSERSPROFILE%\Local Settings\Temp\0a3afffe.com
- 'se####lyfucked.ru':80
- '8.#.8.8':53
- '8.#.4.4':53
- se####lyfucked.ru/and/stat3.php
- DNS ASK se####lyfucked.ru