Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe,"%LOCALAPPDATA%\regry.exe",'
- <File name>.exe
- %LOCALAPPDATA%\regry.exe
- %TEMP%\<File name>.exe
- 'ic###azip.com':80
- DNS ASK ic###azip.com
- '%TEMP%\<File name>.exe'