Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = 'userinit.exe,%WINDIR%\system\bot1.exe,'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = 'userinit.exe,%WINDIR%\system\bot1.exe,<Full path to file>,'
- %WINDIR%\system\bot1.exe
- %WINDIR%\explorer.exe
- %WINDIR%\system\bot1.exe
- %WINDIR%\system\rcx6eaa.tmp
- %TEMP%\bot6f08.tmp
- %TEMP%\bot705e.tmp
- C:\myrep.dat
- C:\myrep.dat
- %TEMP%\bot6f08.tmp
- %TEMP%\bot705e.tmp
- from %WINDIR%\system\rcx6eaa.tmp to %WINDIR%\system\bot1.exe
- 'br###-lab.org':80
- 'br###-lab.org':443
- 'microsoft.com':80
- http://www.br###-lab.org/botnet1/bots_controller.php?gu####################################################################
- http://www.microsoft.com/
- 'br###-lab.org':443
- DNS ASK br###-lab.org
- DNS ASK microsoft.com
- '%WINDIR%\system\bot1.exe'