Technical Information
- '%TEMP%\49442e40_.exe'
- '%TEMP%\3cd60fbf_.exe' /enc 0lzaIqog32irVzNsurBa8gClHri4ohwLj2JOmYir1BRMHtYRzSujO1eGCxmFy9qgP894N9JNetLsR/pCfpcbDKnMaIxuGuNDd/8gp8tHh4CDTjMvamPrRWzy9kANkkDF8e57wgsdPg1l1oPZdF0PMuz33hMZn9OAZzFXxJT6QKwiPtjb93Ic5754fEfiaytV7/n//80abyWcLI17b0CbKZ0hNP5NO9phIcJgEYbpjulvax+ssd+OGUBHYeXuakNdxO0w1i+1GqzRKvZHP+0dVgd93LrX4Mo75bHahm9j5uWtzZmdTcK+UW/ISQi8ngljIIXW3TZMiNm9V2y40aQjjwQteKBvYs
- '%TEMP%\5d037a5a_.exe'
- '%TEMP%\3cd60fbf_.exe' (downloaded from the Internet)
- '%TEMP%\5d037a5a_.exe' (downloaded from the Internet)
- '%TEMP%\49442e40_.exe' (downloaded from the Internet)
- %TEMP%\3cd60fbf_.exe
- %TEMP%\49442e40_.exe
- %TEMP%\5d037a5a_.exe
- 's.####pingchip.info':80
- 'in#####collection.com':80
- 'do######.shoppingchip.info':80
- 'su#####.shoppingchip.info':80
- s.####pingchip.info/
- in#####collection.com/?HI#######################################
- do######.shoppingchip.info/?e=#########################################################################
- su#####.shoppingchip.info/
- DNS ASK s.####pingchip.info
- DNS ASK in#####collection.com
- DNS ASK do######.shoppingchip.info
- DNS ASK su#####.shoppingchip.info