Technical Information
- '%APPDATA%\Roaming\Identities\635410494636850713.exe'
- '%APPDATA%\Roaming\Identities\635410494636850713.exe' (downloaded from the Internet)
- '<SYSTEM32>\rundll32.exe' dfdts.dll,DfdGetDefaultPolicyAndSMART
- %APPDATA%\Roaming\Identities\635410494636850713.exe
- 'ic##mg.ru':80
- ic##mg.ru/update.php
- DNS ASK ic##mg.ru