Technical Information
Malicious functions:
Creates and executes the following:
- '%APPDATA%\Roaming\server.exe'
Executes the following:
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%APPDATA%\Roaming\server.exe" "server.exe" ENABLE
Modifies file system :
Creates the following files:
- %APPDATA%\Roaming\server.exe
Network activity:
Connects to:
- 'hi###.no-ip.biz':5552
UDP:
- DNS ASK dn#.##ftncsi.com
- DNS ASK hi###.no-ip.biz