Technical Information
To ensure autorun and distribution
Modifies the following registry keys
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'explorer' = '%APPDATA%\Explorer\Explorer\RECYCLER\Explorer.exe'
Creates the following files on removable media
- <Drive name for removable media>:\explorer.exe
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\sender.exe
- <Drive name for removable media>:\sender\6.14.13.59.25.jpg
Modifies file system
Creates the following files
- %APPDATA%\explorer\explorer\recycler\explorer.exe
- %APPDATA%\explorer\explorer\recycler\captor\6.14.13.59.25.jpg
Sets the 'hidden' attribute to the following files
- <Drive name for removable media>:\explorer.exe
- <Drive name for removable media>:\autorun.inf
Network activity
Connects to
- 'google.com':80
UDP
- DNS ASK google.com