Technical Information
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe,"%LOCALAPPDATA%\Detrimantor\experto.exe",'
- <File name>.exe
- %LOCALAPPDATA%\detrimantor\experto.exe
- %TEMP%\<File name>.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<File name>.exe.log
- 'co##oso.com':80
- http://www.co##oso.com/PostAccepter.aspx
- DNS ASK co##oso.com
- DNS ASK tr#####edia555.ddns.net
- '%TEMP%\<File name>.exe'