Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Update' = '"%APPDATA%\Microsoft\Windows Update.exe"'
- %APPDATA%\microsoft\<File name>.exe
- %TEMP%\<File name>.exe
- %APPDATA%\microsoft\windows update.exe
- %TEMP%\ixp000.tmp\checker.exe
- %TEMP%\ixp000.tmp\system.yaml
- %TEMP%\ixp000.tmp\system.yaml
- %TEMP%\ixp000.tmp\system.yaml
- http://er####s4vof93y.be/loader/gate
- DNS ASK er####s4vof93y.be
- DNS ASK au##.#iotgames.com
- DNS ASK ra#.####ubusercontent.com
- '%TEMP%\<File name>.exe'
- '%APPDATA%\microsoft\windows update.exe'
- '%APPDATA%\microsoft\<File name>.exe'
- '%TEMP%\ixp000.tmp\checker.exe'
- '%APPDATA%\microsoft\windows update.exe' ' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -nologo -noprofile Start-Process '%TEMP%\\<File name>.exe'; Start-Process '%APPDATA%\Microsoft\\<File name>.exe'