Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Run' = '%TEMP%\Coappearance6\Kriminaliseringens8.exe'
- ieinstal.exe
- %TEMP%\coappearance6\kriminaliseringens8.exe
- 'ne####k.jcgwood.com':2021
- http://wo####place.info/cloud/Host_KKUWzw203.bin
- DNS ASK wo####place.info
- DNS ASK ne####k.jcgwood.com
- '%ProgramFiles(x86)%\internet explorer\ieinstal.exe'