Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'stubpath' = '%TEMP%\apple.exe'
- %TEMP%\apple.exe
- %TEMP%\1.bat
- 'bl##.daum.net':80
- 'ak#####1.blog.163.com':80
- 'op#####12.blog.163.com':80
- http://bl##.daum.net/xml/rss/akxkalx1
- http://bl##.daum.net/xml/rss/opaoxf2
- http://ak#####1.blog.163.com/rss/
- http://op#####12.blog.163.com/rss/
- DNS ASK ex###fo1.org
- DNS ASK bl##.daum.net
- DNS ASK ak#####1.blog.163.com
- DNS ASK op#####12.blog.163.com
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\1.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\1.bat