Technical Information
To ensure autorun and distribution:
Modifies the following registry keys:
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'DF61D2D9' = '%TEMP%\nagiu.exe'
Creates the following services:
- [<HKLM>\SYSTEM\ControlSet001\services\ealydxbyqc] 'Start' = '00000002'
Malicious functions:
Creates and executes the following:
- '%TEMP%\nagiu.exe' -svc
Modifies file system :
Creates the following files:
- %TEMP%\nagiu.exe
Network activity:
UDP:
- DNS ASK dn#.##ftncsi.com
- DNS ASK pi##.himpi.com
Miscellaneous:
Searches for the following windows:
- ClassName: 'Shell_TrayWnd' WindowName: ''