Technical Information
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",zubwdnzeg install worker
- %TEMP%\ins1.tmp
- 'so###scin.cz.cc':80
- so###scin.cz.cc/wlgFIlwgblYk5I0B1uQlp0QOyPFGstWdGxclSELFX+XC1rU2f9fQ8SZFSQvHJG2JbjaAT3EEBTeqAifY8LiCrn0BWwkq5pSe04svBLn2DBpRxw==
- so###scin.cz.cc/laSutKUALgxNQI6z5n8IJR37uP04o/ji2JPvOc5WAHiejiw2XbtEUL8d7Oaw1znwOWOJzZdV2R6rpVnduZ9IhN6r0zGh8QWTavKPb4DIlmHyjMZKKMHeWRgMBBTWuKmBdYuKPHzh0V1kbFufjS+TUhom/QRuJeLlhaJof1APCnX7iEvhluzD8KLcVM8vucNcDYAoV6TNCXs=
- DNS ASK so###scin.cz.cc
- ClassName: 'Shell_TrayWnd' WindowName: ''