Technical Information
To ensure autorun and distribution:
Creates or modifies the following files:
- %HOMEPATH%\Start Menu\Programs\Startup\Shortcut to startup_local.lnk
Modifies file system :
Creates the following files:
- <SYSTEM32>\ipsecstap.dat
Network activity:
UDP:
- DNS ASK 1.####.3322.org.cn
- DNS ASK 2.####.3322.org.cn
- DNS ASK te##.#322.org.cn
- '<Private IP address>':1036