Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = '<SYSTEM32>\sibofud.dll'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'LoadAppInit_DLLs' = '00000001'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'lazizoh' = 'Rundll32.exe "<SYSTEM32>\sibofud.dll" s'
- %WINDIR%\syswow64\sibofud.dll
- DNS ASK my####rnetcmd.com
- '%WINDIR%\syswow64\rundll32.exe' "<SYSTEM32>\sibofud.dll" s