Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SlitherIO' = '"%APPDATA%\slitherio\slitherio.exe"'
- '%APPDATA%\slitherio\slitherio.exe' "/c=" "/p=" "/i=1" "/ep=AngarCl.exe" "/ew=" "/em=<Virus name>.exe" "/dm=<Full path to virus>"
- %APPDATA%\slitherio\Newtonsoft.Json.xml
- %APPDATA%\slitherio\OSVersionInfo.dll
- %APPDATA%\slitherio\e.list
- %APPDATA%\slitherio\Newtonsoft.Json.dll
- %TEMP%\nsy2.tmp\nsProcess.dll
- %TEMP%\nsy2.tmp\System.dll
- %APPDATA%\slitherio\slitherio.exe
- %TEMP%\nsy2.tmp\System.dll
- %TEMP%\nsy2.tmp\nsProcess.dll
- 'sl###ermon.io':443
- 'wp#d':80
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK sl###ermon.io
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: 'SlitherIO Launcher'