Technical Information
Malicious functions:
Terminates or attempts to terminate
the following user processes:
- chrome.exe
Modifies file system :
Creates the following files:
- %TEMP%\Extensions\script.js
- %TEMP%\Extensions\manifest.json
- %TEMP%\Extensions\Preferences
- %TEMP%\Extensions\background.js
- %TEMP%\Extensions\icon.png
- %TEMP%\Extensions\jquery-1.9.1.min.js
Network activity:
Connects to:
- 's4##dia.ru':80
TCP:
HTTP GET requests:
- s4##dia.ru/Extensions/script.js
- s4##dia.ru/Extensions/manifest.json
- s4##dia.ru/Extensions/Preferences
- s4##dia.ru/Extensions/background.js
- s4##dia.ru/Extensions/icon.png
- s4##dia.ru/Extensions/jquery-1.9.1.min.js
UDP:
- DNS ASK s4##dia.ru