Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Default Key' = '%APPDATA%\Default Folder\Default File.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rewrwertw' = '%HOMEPATH%\My Documents\My Pictures\gtryhreye.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'rewrwertw' = '%HOMEPATH%\My Documents\My Pictures\gtryhreye.exe'
- '%HOMEPATH%\My Documents\My Pictures\gtryhreye.exe'
- %APPDATA%\Imminent\Logs\03-09-2016
- %APPDATA%\Default Folder\Default File.exe
- %HOMEPATH%\My Documents\My Pictures\gtryhreye.exe
- 'ja####6.duckdns.org':7373
- DNS ASK ja####6.duckdns.org