Technical Information
- [HKLM\System\CurrentControlSet\Services\RpcIocator] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\RpcIocator] 'ImagePath' = '%WINDIR%\SysWOW64\Iocator.exe'
- 'RpcIocator' %WINDIR%\SysWOW64\Iocator.exe
- '%WINDIR%\syswow64\net.exe' stop RpcIocator
- %WINDIR%\syswow64\iocator.exe
- %WINDIR%\syswow64\a.exe
- %TEMP%\~176.bat
- %TEMP%\~176.bat
- '<LOCALNET>.18.2':80
- DNS ASK 16#.com
- DNS ASK mo###2.vicp.net
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\a.exe'
- '%WINDIR%\syswow64\iocator.exe' /install
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\~176.bat "<SYSTEM32>\a.exe"
- '%WINDIR%\syswow64\net1.exe' stop RpcIocator
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\~176.bat "<SYSTEM32>\a.exe"' (with hidden window)