Technical Information
- '%TEMP%\tmpDD83.exe' /s /t /i NationZoom /u http://www.ch####wnload.com/index.php /ta
- '%TEMP%\Download_68A1\<Virus name>.exe' --elevated
- '%TEMP%\<Virus name>.exe'
- %APPDATA%\Roaming\Oxy\config.xml
- %TEMP%\<Virus name>_002548.log
- %TEMP%\tmpDD83.exe
- %TEMP%\<Virus name>.exe
- %TEMP%\Download_68A1\<Virus name>.exe
- %TEMP%\htmlayout.dll
- %TEMP%\<Virus name>_002548.log
- DNS ASK www.ch####wnload.com
- DNS ASK dn#.##ftncsi.com
- DNS ASK www.ma###soth.com
- ClassName: 'Shell_TrayWnd' WindowName: ''