Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\targetsite.vbs
- %WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe
- [HKCU\Software\FTPWare\COREFTP\Sites\]
- [HKCU\Software\Martin Prikryl\WinSCP 2\Sessions\]
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %APPDATA%\targetsite.exe
- %APPDATA%\microsoft\windows\templates\dbs\logindata
- %APPDATA%\microsoft\windows\templates\dbs\webdata
- 'ar###.com.pe':443
- 'x1.#.lencr.org':80
- 'sh##ip.net':80
- http://x1.#.lencr.org/
- http://sh##ip.net/
- 'ar###.com.pe':443
- DNS ASK ar###.com.pe
- DNS ASK x1.#.lencr.org
- DNS ASK sh##ip.net
- '%WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe'