Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '11f86284' = '%LOCALAPPDATA%\Amp\comhl.exe'
- %LOCALAPPDATA%\amp\comhl.exe
- %LOCALAPPDATA%\amp\zcomhl.exe
- %LOCALAPPDATA%\amp\log.dat
- http://www.se###stival.com/wp-content/plugins/WPSecurity/load.php
- http://nm####rdesign.lu/wp-content/plugins/WPSecurity/load.php
- DNS ASK se###stival.com
- DNS ASK nm####rdesign.lu
- '%LOCALAPPDATA%\amp\comhl.exe'
- '%WINDIR%\syswow64\cmd.exe' /c type "<Full path to file>" > "%LOCALAPPDATA%\Amp\comhl.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c type "<Full path to file>" > "%LOCALAPPDATA%\Amp\zcomhl.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c pushd %LOCALAPPDATA%\Amp & start comhl.exe & popd' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c type "<Full path to file>" > "%LOCALAPPDATA%\Amp\comhl.exe"
- '%WINDIR%\syswow64\cmd.exe' /c type "<Full path to file>" > "%LOCALAPPDATA%\Amp\zcomhl.exe"
- '%WINDIR%\syswow64\cmd.exe' /c pushd %LOCALAPPDATA%\Amp & start comhl.exe & popd