Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Uvwxya Cdefghij Lmn] 'ImagePath' = '%WINDIR%\System.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Uvwxya Cdefghij Lmn] 'Start' = '00000002'
- '%WINDIR%\System.exe'
- %WINDIR%\System.exe
- from <Full path to virus> to %TEMP%\1801bc
- 'localhost':811
- '<Private IP address>':822
- 'hm##.yiqing.pw':833
- 'li###.yiqing.pw':1234
- DNS ASK li###.yiqing.pw
- DNS ASK hm##.yiqing.pw