Technical Information
To ensure autorun and distribution:
Creates the following files on removable media:
- <Drive name for removable media>:\CyberHackers.exe
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\UsbDrivers.exe
Modifies file system :
Creates the following files:
Sets the 'hidden' attribute to the following files:
- <Drive name for removable media>:\CyberHackers.exe
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\UsbDrivers.exe
Network activity:
Connects to:
- 'ge####kerdns.co.cc':80
TCP:
HTTP GET requests:
- ge####kerdns.co.cc/priv9/bots.php?na###################
UDP:
- DNS ASK ge####kerdns.co.cc