Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'CryptoLocker' = '"%APPDATA%\{F2044B43-EB9D-E0C9-83C2-EBCBF7C6A9EE}.exe"'
- '%APPDATA%\{F2044B43-EB9D-E0C9-83C2-EBCBF7C6A9EE}.exe' /w00000078
- '%APPDATA%\{F2044B43-EB9D-E0C9-83C2-EBCBF7C6A9EE}.exe' "/r<Full path to virus>"
- %APPDATA%\{F2044B43-EB9D-E0C9-83C2-EBCBF7C6A9EE}.exe
- %APPDATA%\{F2044B43-EB9D-E0C9-83C2-EBCBF7C6A9EE}.exe
- 'hq###shdjahp.ru':80
- 'gg####wtceca.biz':80
- 'wd####iymsyi.co.uk':80
- 'jh####meeqls.org':80
- 'gr####cqidrg.net':80
- 'ev####apslpg.co.uk':80
- 'eh####fmykfm.org':80
- 'fh####rhbhmq.com':80
- 'fg####kyahuv.info':80
- 'ld####rdhvqx.info':80
- 'si####mutlns.info':80
- 'rx####siluxy.co.uk':80
- 'ue####rtwqsx.net':80
- 'tt####xhoade.com':80
- 'bj####kcyqqh.org':80
- 'lr####jinjxm.net':80
- 'yy####nxpxen.com':80
- 'nn###mohqodr.ru':80
- 'yn####fdvllc.biz':80
- 'oe####bleeoo.co.uk':80
- 'nv####ygttxt.org':80
- 'qa####nxkykc.com':80
- 'pq####uxpnfi.info':80
- 'mj###cftikha.ru':80
- 'sb####xasjkp.net':80
- 'as####fsixcyosb.org':80
- 'la####mtnycg.biz':80
- 'kn####shcplm.net':80
- 'rm####hkvibv.net':80
- 'xp####qeuafp.net':80
- 'km####xgbkna.com':80
- 'dw###fudroaw.ru':80
- 'll####dschdj.biz':80
- 'wq####lrtdpg.info':80
- 'ic###lbcrrbg.ru':80
- 'ug####onkkdm.biz':80
- 'jb####gosoqp.co.uk':80
- 'vf####talhsv.org':80
- DNS ASK hq###shdjahp.ru
- DNS ASK gg####wtceca.biz
- DNS ASK wd####iymsyi.co.uk
- DNS ASK jh####meeqls.org
- DNS ASK gr####cqidrg.net
- DNS ASK ev####apslpg.co.uk
- DNS ASK eh####fmykfm.org
- DNS ASK fh####rhbhmq.com
- DNS ASK fg####kyahuv.info
- DNS ASK ld####rdhvqx.info
- DNS ASK si####mutlns.info
- DNS ASK rx####siluxy.co.uk
- DNS ASK ue####rtwqsx.net
- DNS ASK tt####xhoade.com
- DNS ASK bj####kcyqqh.org
- DNS ASK lr####jinjxm.net
- DNS ASK yy####nxpxen.com
- DNS ASK nn###mohqodr.ru
- DNS ASK yn####fdvllc.biz
- DNS ASK oe####bleeoo.co.uk
- DNS ASK nv####ygttxt.org
- DNS ASK qa####nxkykc.com
- DNS ASK pq####uxpnfi.info
- DNS ASK mj###cftikha.ru
- DNS ASK sb####xasjkp.net
- DNS ASK as####fsixcyosb.org
- DNS ASK la####mtnycg.biz
- DNS ASK kn####shcplm.net
- DNS ASK rm####hkvibv.net
- DNS ASK xp####qeuafp.net
- DNS ASK km####xgbkna.com
- DNS ASK dw###fudroaw.ru
- DNS ASK ll####dschdj.biz
- DNS ASK wq####lrtdpg.info
- DNS ASK ic###lbcrrbg.ru
- DNS ASK ug####onkkdm.biz
- DNS ASK jb####gosoqp.co.uk
- DNS ASK vf####talhsv.org
- ClassName: 'Indicator' WindowName: '(null)'