Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'dmutsapi' = '%APPDATA%\corppres\aaaanfig.exe'
- '<SYSTEM32>\nslookup.exe' myip.opendns.com resolver1.opendns.com
- '<SYSTEM32>\cmd.exe' /C "nslookup myip.opendns.com resolver1.opendns.com > %TEMP%\E3F5.bi1"
- '<SYSTEM32>\cmd.exe' /C "echo -------- >> %TEMP%\E3F5.bi1"
- '<SYSTEM32>\cmd.exe' /C "echo -------- >> %TEMP%\E3E5.bi1"
- '<SYSTEM32>\cmd.exe' /C ""%APPDATA%\corppres\aaaanfig.exe" "<Full path to virus>""
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\190C\1.bat" "%APPDATA%\corppres\aaaanfig.exe" "<Full path to virus>""
- '<SYSTEM32>\cmd.exe' /C "nslookup myip.opendns.com resolver1.opendns.com > %TEMP%\E3E5.bi1"
- '%APPDATA%\corppres\aaaanfig.exe' "<Full path to virus>"
- %WINDIR%\Explorer.EXE
- opera.exe
- %TEMP%\E3F5.bi1
- %TEMP%\676.bin
- %TEMP%\1C1F.bin
- %APPDATA%\corppres\aaaanfig.exe
- %TEMP%\190C\1.bat
- %TEMP%\E3E5.bi1
- %TEMP%\676.bin
- %TEMP%\E3F5.bi1
- %TEMP%\E3E5.bi1
- 'ci#####eimballaggi.it':80
- 'vv##rvop.at':80
- 're#####r1.opendns.com':53
- 'localhost':1036
- 'ar####epassione.com':80
- 'de#####rceitalia.com':80
- http://ci#####eimballaggi.it/tosf/Umsk493skLAs.so
- http://vv##rvop.at/statfiles/pz/tr.so
- http://ar####epassione.com/documenti/tr.so
- http://de#####rceitalia.com/_vti_txt/Js.dll
- DNS ASK vv##rvop.at
- DNS ASK re#####r1.opendns.com
- DNS ASK bo##bom.at
- DNS ASK ar####epassione.com
- DNS ASK de#####rceitalia.com
- DNS ASK ci#####eimballaggi.it
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'ProgMan' WindowName: ''