Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '' = '%APPDATA%\iexplorer.exe'
- %APPDATA%\phoenix\my\1.0.0.0\tmp4571.scr
- %APPDATA%\iexplorer.exe
- 'sm##.gmail.com':587
- DNS ASK sm##.gmail.com
- '%APPDATA%\phoenix\my\1.0.0.0\tmp4571.scr'
- '%APPDATA%\iexplorer.exe'
- '%APPDATA%\phoenix\my\1.0.0.0\tmp4571.scr' ' (with hidden window)