Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4\Parameters] 'ServiceDll' = '<SYSTEM32>\hrubp.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'Start' = '00000002'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\hrubp.dll,WinWatchGetClipList 1140
- %TEMP%\124625.log
- <SYSTEM32>\config\SysEvent.Evt
- <SYSTEM32>\config\SecEvent.Evt
- <SYSTEM32>\config\AppEvent.Evt
- from %TEMP%\124625.log to <SYSTEM32>\hrubp.dll
- 'hn####2009.3322.org':6666
- DNS ASK hn####2009.3322.org