Technical Information
- %APPDATA%\Server.exe
- %APPDATA%\7za.exe "x" "-y" "%APPDATA%\Server.7z" "-pHVLnt5Dy"
- ICQ.exe
- <Current directory>\Server.exe
- %TEMP%\CRNJEUFU
- %APPDATA%\7za.exe
- %APPDATA%\Server.txt
- %APPDATA%\Server.7z
- %APPDATA%\Server.exe
- %APPDATA%\7za.exe
- from <Current directory>\Server.exe to %APPDATA%\Server.exe
- from %APPDATA%\Server.txt to %APPDATA%\Server.7z
- 'eu###lge.com':80
- 'au######on.whatismyip.com':80
- 'wp#d':80
- eu###lge.com/logs/log/index.php?ac##################################################
- au######on.whatismyip.com/n09230945.asp
- wp#d/wpad.dat
- DNS ASK eu###lge.com
- DNS ASK au######on.whatismyip.com
- DNS ASK wp#d