Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'joeblack' = '%APPDATA%\joeblack\joeblack.exe'
- %TEMP%\nsjc0b0.tmp\inetload.dll
- %APPDATA%\joeblack\joeblack.exe
- %TEMP%\nsjc0b0.tmp\locationcount.dll
- %TEMP%\nsjc0b0.tmp\selfdelete.dll
- C:\delus.bat
- %TEMP%\nsjc0b0.tmp\inetload.dll
- %TEMP%\nsjc0b0.tmp\locationcount.dll
- %TEMP%\nsjc0b0.tmp\selfdelete.dll
- DNS ASK up####.enprivacy.com
- DNS ASK 00###0.co.kr
- DNS ASK 11###0.co.kr
- DNS ASK 00###1.co.kr
- '%APPDATA%\joeblack\joeblack.exe'
- '%WINDIR%\syswow64\cmd.exe' /c \DelUS.bat
- '%WINDIR%\syswow64\cmd.exe' /c \DelUS.bat' (with hidden window)