Technical Information
- [<HKLM>\System\CurrentControlSet\Services\MsRkNrL] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\MsRkNrL] 'ImagePath' = '<SYSTEM32>\wscript.exe //B "C:\autoexec.vbs"'
- 'MsRkNrL' <SYSTEM32>\wscript.exe //B "C:\autoexec.vbs"
- '<SYSTEM32>\wscript.exe' //B "%TEMP%\rknrl.vbs"
- %TEMP%\dm6331.tmp
- %WINDIR%\temp\rada320e.tmp
- %WINDIR%\temp\rada6f4f.tmp
- %WINDIR%\temp\rad938d9.tmp
- %WINDIR%\temp\rad6c629.tmp
- %WINDIR%\temp\radb75cb.tmp
- %WINDIR%\temp\rad52528.tmp
- %WINDIR%\temp\radbdcb9.tmp
- %TEMP%\rad828ea.tmp
- %WINDIR%\temp\rad78828.tmp
- %WINDIR%\temp\radd22d7.tmp
- %WINDIR%\temp\radf6c4a.tmp
- %WINDIR%\temp\rad87379.tmp
- %WINDIR%\temp\rad1ed29.tmp
- %WINDIR%\temp\rad87cd8.tmp
- %TEMP%\radbd2d9.tmp
- %TEMP%\rad7f608.tmp
- %WINDIR%\temp\rad8a14a.tmp
- %TEMP%\rad4cab5.tmp
- %WINDIR%\temp\raddf249.tmp
- %WINDIR%\temp\rad85ab0.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0o42hqll\rknrl[1].vbs
- C:\dm6331.tmp
- C:\autoexec.vbs
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\dm6331[1].tmp
- %WINDIR%\temp\rad739bb.tmp
- %WINDIR%\temp\rad43b8c.tmp
- %WINDIR%\temp\rad5e17a.tmp
- %TEMP%\rad71f3a.tmp
- %TEMP%\chrome.exe
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\t5levnel\dm6331[1].tmp
- %WINDIR%\temp\rad3717f.tmp
- %WINDIR%\temp\rad7e840.tmp
- %WINDIR%\temp\radb563d.tmp
- %WINDIR%\temp\rada569f.tmp
- %WINDIR%\temp\rad0dd39.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\playback[2].php
- %WINDIR%\temp\rad73b19.tmp
- %TEMP%\rad676bb.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\playback[1].php
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\rknrl[1].vbs
- %WINDIR%\temp\radb636d.tmp
- %WINDIR%\temp\rad35589.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\t5levnel\url[1].htm
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\api[1]
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\t5levnel\api[1]
- %TEMP%\radfab66.tmp
- %WINDIR%\temp\rad4fa3f.tmp
- %TEMP%\rad29b9a.tmp
- %TEMP%\radf30bb.tmp
- %TEMP%\radf88eb.tmp
- %WINDIR%\temp\rknrl.vbs
- %WINDIR%\temp\winstart.vbs
- %WINDIR%\temp\dm6331.tmp
- %TEMP%\winstart.vbs
- %TEMP%\rknrl.vbs
- %TEMP%\rad975aa.tmp
- %WINDIR%\temp\rad76a71.tmp
- %WINDIR%\temp\rade9499.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\url[1].htm
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\t5levnel\rknrl[1].vbs
- %WINDIR%\temp\rade8e9c.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\rknrl[1].vbs
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\dm6331[1].tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0o42hqll\playback[1].php
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0o42hqll\dm6331[1].tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\playback[1].php
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\api[1]
- %WINDIR%\temp\rad4b0fc.tmp
- %WINDIR%\temp\rad4ebd9.tmp
- %WINDIR%\temp\radfda4a.tmp
- %WINDIR%\temp\radfcacf.tmp
- %WINDIR%\temp\rad3c16e.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\url[1].htm
- %WINDIR%\temp\rad24b10.tmp
- %WINDIR%\temp\radea93b.tmp
- %WINDIR%\temp\radaa881.tmp
- %WINDIR%\temp\rad3d45e.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0o42hqll\api[1]
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\dm6331[2].tmp
- C:\autoexec.vbs
- C:\dm6331.tmp
- %TEMP%\dm6332.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0o42hqll\api[1]
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0o42hqll\rknrl[1].vbs
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\t5levnel\dm6331[1].tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\playback[2].php
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\playback[1].php
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\url[1].htm
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\dm6331[1].tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0o42hqll\playback[1].php
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\rknrl[1].vbs
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\t5levnel\rknrl[1].vbs
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\rknrl[1].vbs
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0o42hqll\dm6331[1].tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\playback[1].php
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\api[1]
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\url[1].htm
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\t5levnel\url[1].htm
- %WINDIR%\temp\dm6332.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\api[1]
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\t5levnel\api[1]
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\dm6331[1].tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\dm6331[2].tmp
- from %TEMP%\radf88eb.tmp to %TEMP%\dm6332.tmp
- from %WINDIR%\temp\rad35589.tmp to %WINDIR%\temp\dm6332.tmp
- %TEMP%\dm6332.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\t5levnel\api[1]
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\api[1]
- %WINDIR%\temp\dm6332.tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\t5levnel\rknrl[1].vbs
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0o42hqll\dm6331[1].tmp
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\rknrl[1].vbs
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\api[1]
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\59o0eoqa\url[1].htm
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\url[1].htm
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\t5levnel\url[1].htm
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\playback[1].php
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0o42hqll\rknrl[1].vbs
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\0o42hqll\playback[1].php
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\<INETFILES>\content.ie5\jh3iwefd\rknrl[1].vbs
- 'ap#.##herscan.io':80
- 'ai########ill.aigoingtokill.club':80
- 'm.#####ngtokill.club':80
- http://ap#.##herscan.io/api?mo#############################################################################
- http://ai########ill.aigoingtokill.club/ctrl/playback.php
- http://ai########ill.aigoingtokill.club/ctrl/file/DM6331.TMP
- http://ai########ill.aigoingtokill.club/ctrl/file/rknrl.vbs
- http://ai########ill.aigoingtokill.club/ctrl/url.html
- http://ai########ill.aigoingtokill.club/ctrl/pool.txt
- http://ai########ill.aigoingtokill.club/ctrl/Normal.doc
- DNS ASK ap#.##herscan.io
- DNS ASK ai########ill.aigoingtokill.club
- DNS ASK m.#####ngtokill.club
- '<SYSTEM32>\wscript.exe' //B "%WINDIR%\TEMP\rknrl.vbs"
- '<SYSTEM32>\wscript.exe' //B "%TEMP%\winstart.vbs"
- '<SYSTEM32>\wscript.exe' //B "%WINDIR%\TEMP\winstart.vbs"
- '<SYSTEM32>\wscript.exe' //B "%TEMP%\rknrl.vbs"' (with hidden window)