Technical Information
- [HKLM\System\CurrentControlSet\Services\ICF] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\ICF] 'ImagePath' = '<SYSTEM32>\icf.exe.exe:exe.exe'
- 'ICF' <SYSTEM32>\icf.exe.exe:exe.exe
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\syswow64\icf.exe.exe:exe.exe
- <Current directory>\2359299.bat
- DNS ASK yo####zankaza.net
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\2359299.bat
- '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\2359299.bat' (with hidden window)