Technical Information
- %WINDIR%\tasks\rdsj.job
- <SYSTEM32>\tasks\rdsj
- %ALLUSERSPROFILE%\klmno\rdsj.exe
- http://17#.#5.193.9/tor/status-vote/current/consensus
- http://10#.#89.10.157/tor/server/fp/8e96a38f3c4de11658592c1ab38c90aec932710e
- http://10#.#89.10.157/tor/server/fp/18eae30a4585beb0d63d36bcfe3f9ca786cb55c7
- http://10#.#89.10.157/tor/server/fp/874f20c962dce51cec63d248ca15027b60e5233c
- http://10#.#89.10.157/tor/server/fp/f5f4019509109a07e90c45a022ceed9eca1643c8
- DNS ASK ad###175x.xyz
- DNS ASK se###278x.xyz
- DNS ASK ap#.#pify.org
- DNS ASK ip#.#eeip.org
- '%ALLUSERSPROFILE%\klmno\rdsj.exe' start
- '%ALLUSERSPROFILE%\klmno\rdsj.exe' start' (with hidden window)