Technical Information
Modifies file system :
Creates the following files:
- <Current directory>\temp.hiv
- <SYSTEM32>\Explorer.exe
Sets the 'hidden' attribute to the following files:
- <SYSTEM32>\Explorer.exe
Deletes the following files:
- <Current directory>\temp.hiv
Network activity:
Connects to:
- 'po##.#edians.net':443
UDP:
- DNS ASK po##.#edians.net