Technical Information
- [<HKLM>\System\CurrentControlSet\Services\YuDCSG.dll] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\YuDCSG.dll] 'ImagePath' = '<SYSTEM32>\regsvr32.exe "<SYSTEM32>\QgxUQyMDyFGr\YuDCSG.dll"'
- 'YuDCSG.dll' <SYSTEM32>\regsvr32.exe "<SYSTEM32>\QgxUQyMDyFGr\YuDCSG.dll"
- '<SYSTEM32>\regsvr32.exe' ..\xwnlm.ocx
- %HOMEPATH%\xwnlm.ocx
- <Current directory>\da831000
- from %HOMEPATH%\xwnlm.ocx to <SYSTEM32>\qgxuqymdyfgr\yudcsg.dll
- <PATH_SAMPLE>.xls
- 'li##us.com':443
- 'kr###str.com':80
- http://kr###str.com/tr/bbRjEuBFYBX4Oiod/
- 'li##us.com':443
- DNS ASK li##us.com
- DNS ASK kr###str.com
- '<SYSTEM32>\regsvr32.exe' ..\xwnlm.ocx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\QgxUQyMDyFGr\YuDCSG.dll"