Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.js
- unc\zxsszvu*\mailslot\net\netlogon
- 'ra#.####ubusercontent.com':443
- 'ip##fo.io':80
- 'ip##fo.io':443
- 'localhost':80
- http://ip##fo.io/ip
- http://ip##fo.io/country
- 'ra#.####ubusercontent.com':443
- 'ip##fo.io':443
- DNS ASK ra#.####ubusercontent.com
- DNS ASK ip##fo.io
- '<SYSTEM32>\cmd.exe' /C net view > "%TEMP%\rad7CAE0.tmp"
- '<SYSTEM32>\net.exe' view
- '<SYSTEM32>\cmd.exe' /C net view > "%TEMP%\rad7CAE0.tmp"' (with hidden window)