Technical Information
- '<LS_APPDATA>\{QE2B3QE0-809M-W8W9-GU74-M6TM7M4G2SJV}\423u6xs.exe'
- '<LS_APPDATA>\{QE2B3QE0-809M-W8W9-GU74-M6TM7M4G2SJV}\1fzwmc27z1.exe'
- '<LS_APPDATA>\{QE2B3QE0-809M-W8W9-GU74-M6TM7M4G2SJV}\423u6xs.exe' (downloaded from the Internet)
- '<LS_APPDATA>\{QE2B3QE0-809M-W8W9-GU74-M6TM7M4G2SJV}\1fzwmc27z1.exe' (downloaded from the Internet)
- '<SYSTEM32>\cmd.exe' /C <Current directory>\<Virus name>.bat
- '<SYSTEM32>\cmd.exe' /C Start <LS_APPDATA>\{QE2B3QE0-809M-W8W9-GU74-M6TM7M4G2SJV}\423u6xs.exe
- '<SYSTEM32>\cmd.exe' /C Start <LS_APPDATA>\{QE2B3QE0-809M-W8W9-GU74-M6TM7M4G2SJV}\1FZWMC~1.EXE
- <Current directory>\<Virus name>.bat
- <Current directory>\<Virus name>.pdf
- <LS_APPDATA>\{QE2B3QE0-809M-W8W9-GU74-M6TM7M4G2SJV}\1fzwmc27z1.exe
- <LS_APPDATA>\{QE2B3QE0-809M-W8W9-GU74-M6TM7M4G2SJV}\423u6xs.exe
- 'mi####lcba.hol.es':80
- 're####a2013.hol.es':80
- http://re####a2013.hol.es/whats/contatos.bmp
- http://re####a2013.hol.es/zello/messenger.bmp
- http://mi####lcba.hol.es/adm/contador.php
- DNS ASK mi####lcba.hol.es
- DNS ASK re####a2013.hol.es
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'TFrmRepEvent' WindowName: ''