Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Explorer GUI Unit] 'Start' = '00000002'
- '<SYSTEM32>\explore.exe'
- '<SYSTEM32>\ping.exe' 0.0.0.0
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\temp4785.bat" "
- '<SYSTEM32>\ipconfig.exe' /flushdns
- %TEMP%\temp4785.bat
- <SYSTEM32>\explore.exe
- 'my###.unibaq.com':47221
- DNS ASK my###.unibaq.com