Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'driversnw' = '%APPDATA%\DriversNW\drivernwx.exe'
- %WINDIR%\syswow64\svchost.exe
- %APPDATA%\driversnw\drivernwx.exe
- 'a5###3d2e1.com':3360
- DNS ASK a5###3d2e1.com
- DNS ASK google.com
- '%WINDIR%\syswow64\ping.exe' google.com' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "driversnw" /t REG_SZ /F /D "%APPDATA%\DriversNW\drivernwx.exe' (with hidden window)
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\ping.exe' google.com
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "driversnw" /t REG_SZ /F /D "%APPDATA%\DriversNW\drivernwx.exe