Technical Information
- '<SYSTEM32>\notepad.exe'
- '<SYSTEM32>\net1.exe' stop MpsSvc
- '<SYSTEM32>\net.exe' stop MpsSvc
- <SYSTEM32>\notepad.exe
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startupx\system.pif
- <Full path to virus>
- '80.##1.156.180':1604
- '<Private IP address>':1604
- 'localhost':5357
- 'localhost':58088
- 'localhost':57755