Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ec525f4' = '%APPDATA%\ec525f4.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ec525f' = 'C:\ec525f4\ec525f4.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\ec525f4.exe
- System Restore (SR)
- '%TEMP%\3.tmp'
- '%TEMP%\2.tmp'
- '<SYSTEM32>\svchost.exe' netsvcs
- '<SYSTEM32>\vssadmin.exe' Delete Shadows /All /Quiet
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\msiexec.exe'
- <SYSTEM32>\msiexec.exe
- <SYSTEM32>\svchost.exe
- C:\ec525f4\ec525f4.exe
- %APPDATA%\ec525f4.exe
- %TEMP%\2.tmp
- %TEMP%\3.tmp
- %TEMP%\2.tmp
- 'my####rnalip.com':80
- 'ip##ddr.es':80
- http://my####rnalip.com/raw
- http://ip##ddr.es/
- DNS ASK cu###yip.com
- DNS ASK microsoft.com
- DNS ASK el##son.com
- DNS ASK ip##ddr.es
- DNS ASK my####rnalip.com
- DNS ASK up####.microsoft.com
- ClassName: 'Indicator' WindowName: ''