Technical Information
- %WINDIR%\tasks\savehooray.job
- <SYSTEM32>\tasks\savehooray
- [HKLM\SYSTEM\CurrentControlSet\Services\Mysterious Regret] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\Mysterious Regret] 'ImagePath' = '%APPDATA%\Mysterious Regret\Mysterious Regret.exe'
- 'Mysterious Regret' %APPDATA%\Mysterious Regret\Mysterious Regret.exe
- %ALLUSERSPROFILE%\{a51a940c-a8ea-3a6a-a51a-a940ca8e5032}\<File name>.exe
- %APPDATA%\mysterious regret\mysterious regret.exe
- %ALLUSERSPROFILE%\{a51a940c-a8ea-3a6a-a51a-a940ca8e5032}\<File name>.dat
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %APPDATA%\mysterious regret\j8.dat
- DNS ASK ge####uesee.info
- DNS ASK al####el-pro.com
- DNS ASK mo###odel.biz
- DNS ASK fi####usapro.info
- '%APPDATA%\mysterious regret\mysterious regret.exe'