Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ec525f4' = '%APPDATA%\ec525f4.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ec525f' = 'C:\ec525f4\ec525f4.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\ec525f4.exe
- System Restore (SR)
- '<SYSTEM32>\vssadmin.exe' Delete Shadows /All /Quiet
- '<SYSTEM32>\svchost.exe' netsvcs
- '%WINDIR%\explorer.exe'
- <SYSTEM32>\svchost.exe
- %APPDATA%\ec525f4.exe
- C:\ec525f4\ec525f4.exe
- 'me###ort.net':80
- 'su######seoservices.com.au':80
- 'hc###oup.net':80
- 'pr#########alsrarecoininvestments.com':80
- 'ol##u.com':80
- 'ma####ldakariri.net':80
- 'ca#####eniordogfood.com':80
- 'de####ondock.com':80
- 'do####ithere.com':80
- 'dy####lawoffice.com':80
- 'ma###e-club.net':80
- 'ca####nblowdri.com':80
- 'gr###bsm.net':80
- 'oh######estateinvestor.com':80
- 'hi###ins.com':80
- 'bu####flymedia.az':80
- 'in##sof.com':80
- 'dr#####aparchitects.com':80
- 'gj##an.com':80
- 'di###ichluy.net':80
- 'dr#####shlaundry.com':80
- 'cr###track.com':80
- 'al##obs.com':80
- 'ja###angela.com':80
- 'dc####members.com':80
- 'my####rnalip.com':80
- 'ip##ddr.es':80
- 'gr###sbo.org':80
- 'cu###yip.com':80
- 'do####ligames.org':80
- 'dl####igninc.net':80
- 'cr####voplasma.com':80
- 'di#####hersreviews.org':80
- 'dh####utions.net':80
- 'sp##dna.com':80
- 'fu#####deosonline.net':80
- 'ca######iainsuranceco.com':80
- 'cr#######ore-repair-help.com':80
- 'fo###iski.com':80
- http://cu###yip.com/
- http://my####rnalip.com/raw
- http://ip##ddr.es/
- http://al##obs.com/img4.php?z=############
- http://ja###angela.com/img5.php?b=############
- http://dr#####shlaundry.com/wp-content/img1.php?z=############
- http://do####ligames.org/img1.php?f=############
- http://fo###iski.com/img5.php?h=############
- http://fu#####deosonline.net/img2.php?a=############
- http://ca######iainsuranceco.com/img4.php?t=############
- http://cr###track.com/img2.php?i=############
- http://ma###e-club.net/img3.php?z=##############
- http://ca####nblowdri.com/img4.php?n=##############
- http://hi###ins.com/img4.php?c=##############
- http://oh######estateinvestor.com/img1.php?d=##############
- http://dc####members.com/img4.php?z=############
- http://gr###sbo.org/img5.php?z=############
- http://gr###bsm.net/img4.php?y=##############
- http://cr#######ore-repair-help.com/img4.php?g=############
- http://ol##u.com/img5.php?h=############
- http://de####ondock.com/img2.php?q=############
- http://do####ithere.com/tools/img2.php?w=############
- http://su######seoservices.com.au/img5.php?v=############
- http://hc###oup.net/img5.php?c=############
- http://pr#########alsrarecoininvestments.com/img2.php?l=############
- http://me###ort.net/img2.php?g=############
- http://ma####ldakariri.net/img2.php?m=############
- http://dl####igninc.net/img3.php?l=############
- http://cr####voplasma.com/televisa/img1.php?h=############
- http://sp##dna.com/img1.php?y=############
- http://dh####utions.net/img5.php?j=############
- http://ca#####eniordogfood.com/img2.php?n=############
- http://di###ichluy.net/utf.php?q=############
- http://di#####hersreviews.org/img3.php?y=############
- http://cr#######ore-repair-help.com/img4.php?a=##############
- http://fo###iski.com/img5.php?x=##############
- http://fu#####deosonline.net/img2.php?v=##############
- http://sp##dna.com/img1.php?h=##############
- http://dh####utions.net/img5.php?z=##############
- http://dl####igninc.net/img3.php?u=##############
- http://cr####voplasma.com/televisa/img1.php?v=##############
- http://ca######iainsuranceco.com/img4.php?f=##############
- http://cr###track.com/img2.php?h=##############
- http://dc####members.com/img4.php?x=##############
- http://gr###sbo.org/img5.php?e=##############
- http://dr#####shlaundry.com/wp-content/img1.php?m=##############
- http://do####ligames.org/img1.php?m=##############
- http://al##obs.com/img4.php?f=##############
- http://ja###angela.com/img5.php?p=##############
- http://di#####hersreviews.org/img3.php?q=##############
- http://dy####lawoffice.com/img1.php?s=##############
- http://hc###oup.net/img5.php?i=##############
- http://pr#########alsrarecoininvestments.com/img2.php?g=##############
- http://in##sof.com/img4.php?u=##############
- http://dr#####aparchitects.com/img4.php?o=##############
- http://gj##an.com/img3.php?q=##############
- http://bu####flymedia.az/img2.php?i=##############
- http://me###ort.net/img2.php?a=##############
- http://ma####ldakariri.net/img2.php?v=##############
- http://ca#####eniordogfood.com/img2.php?u=##############
- http://di###ichluy.net/utf.php?h=##############
- http://do####ithere.com/tools/img2.php?e=##############
- http://su######seoservices.com.au/img5.php?i=##############
- http://ol##u.com/img5.php?t=##############
- http://de####ondock.com/img2.php?n=##############
- DNS ASK me###ort.net
- DNS ASK su######seoservices.com.au
- DNS ASK hc###oup.net
- DNS ASK pr#########alsrarecoininvestments.com
- DNS ASK ol##u.com
- DNS ASK ma####ldakariri.net
- DNS ASK ca#####eniordogfood.com
- DNS ASK de####ondock.com
- DNS ASK do####ithere.com
- DNS ASK dy####lawoffice.com
- DNS ASK ma###e-club.net
- DNS ASK ca####nblowdri.com
- DNS ASK gr###bsm.net
- DNS ASK oh######estateinvestor.com
- DNS ASK hi###ins.com
- DNS ASK bu####flymedia.az
- DNS ASK in##sof.com
- DNS ASK dr#####aparchitects.com
- DNS ASK gj##an.com
- DNS ASK di###ichluy.net
- DNS ASK dr#####shlaundry.com
- DNS ASK cr###track.com
- DNS ASK al##obs.com
- DNS ASK ja###angela.com
- DNS ASK dc####members.com
- DNS ASK my####rnalip.com
- DNS ASK ip##ddr.es
- DNS ASK gr###sbo.org
- DNS ASK cu###yip.com
- DNS ASK do####ligames.org
- DNS ASK dl####igninc.net
- DNS ASK cr####voplasma.com
- DNS ASK di#####hersreviews.org
- DNS ASK dh####utions.net
- DNS ASK sp##dna.com
- DNS ASK fu#####deosonline.net
- DNS ASK ca######iainsuranceco.com
- DNS ASK cr#######ore-repair-help.com
- DNS ASK fo###iski.com
- ClassName: 'Indicator' WindowName: ''