Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe,"%APPDATA%\Gftqyx\Wgdlak.exe",'
- %APPDATA%\gftqyx\wgdlak.exe
- '19#.#80.49.17':80
- '19#.#80.49.17':28282
- 'ge###ugin.net':80
- http://19#.#80.49.17/Pruwgxlsz.bmp
- http://ge###ugin.net/json.gp
- '19#.#80.49.17':28282
- DNS ASK ge###ugin.net
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ENC cwB0AGEAcgB0AC0AcwBsAGUAZQBwACAALQBzAGUAYwBvAG4AZABzACAAMgAwAA==' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ENC cwB0AGEAcgB0AC0AcwBsAGUAZQBwACAALQBzAGUAYwBvAG4AZABzACAAMgAwAA==