Technical Information
- %TEMP%\ckzbghairmv1
- %TEMP%\ckzbghairmv2
- %TEMP%\ckzbghairmv2.dll
- '91.##0.14.124':80
- '18#.#27.27.100':80
- http://www.af#####olidaytours.com/g76dbf?lr##############
- http://cl####oevent.com/g76dbf?lr##############
- DNS ASK af#####olidaytours.com
- DNS ASK cl####oevent.com
- '<SYSTEM32>\rundll32.exe' %LOCALAPPDATA%\Temp/CkzBgHAIrmV2.dll,qwerty' (with hidden window)
- '<SYSTEM32>\rundll32.exe' %LOCALAPPDATA%\Temp/CkzBgHAIrmV2.dll,qwerty