Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\webserver] 'Start' = '00000002'
- '%PROGRAM_FILES%\webserver\webserver.exe'
- '<SYSTEM32>\sc.exe' create "webserver" binPath= "%PROGRAM_FILES%\webserver\webserver.exe" type= share start= auto
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Services\webserver" /v FailureActions /t REG_BINARY /d 00000000000000000000000003000000140000000100000060EA00000100000060EA00000100000060EA0000 /f
- '<SYSTEM32>\sc.exe' start "webserver"
- '<SYSTEM32>\reg.exe' add HKLM\Software\Microsoft\Windows\CurrentVersion /v Port /t REG_DWORD /d 534
- '<SYSTEM32>\netsh.exe' firewall add portopening TCP 534 webserver ENABLE
- '<SYSTEM32>\netsh.exe' firewall add portopening TCP 53 webserver ENABLE
- %PROGRAM_FILES%\webserver\webserver.exe
- 'u0###2010u.com':80
- DNS ASK u0###2010u.com
- DNS ASK ao#.com