Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{U511RTRK-AOR6-6BC8-QY7A-07Y0565RHC65}] 'StubPath' = '"<Current directory>\%tasks\.Install\scvhost.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'explorer.exe' = '<Current directory>\%tasks\.Install\scvhost.exe'
- '<Current directory>\%tasks\.Install\scvhost.exe'
- '<Current directory>\%tasks\.Install\scvhost.exe' "<Full path to virus>"
- <Current directory>\%tasks\.Install\.Identifier
- <Current directory>\%tasks\.Install\scvhost.exe
- <Current directory>\%tasks\.Install\.Identifier
- <Current directory>\%tasks\.Install\scvhost.exe
- 'so####os.info.ve':4444
- 'so####os.info.ve':1883
- 'so####os.info.ve':3333
- 'localhost':3360
- 'so####os.info.ve':3360
- DNS ASK so####os.info.ve
- ClassName: 'Indicator' WindowName: ''