Technical Information
- [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] '6k1Dc9YvF' = '%APPDATA%\AGEGE\dJdbu7l70_87qXu9zL7\6k1Dc9YvF.exe'
- %APPDATA%\agege\djdbu7l70_87qxu9zl7\6k1dc9yvf.txt
- %APPDATA%\agege\djdbu7l70_87qxu9zl7\6k1dc9yvf.exe
- %WINDIR%\fleetmissionutils.dll
- %WINDIR%\mywatch.dll
- %LOCALAPPDATA%\1fcbfbff000406f1
- %APPDATA%\agege\djdbu7l70_87qxu9zl7\.lnk
- %APPDATA%\agege\djdbu7l70_87qxu9zl7\.lnk
- '23.##6.57.28':8080
- '23.##6.57.28':12345
- http://23.###.57.28:8080/10x.dll via 23.##6.57.28
- '23.##6.57.28':12345
- ClassName: '' WindowName: ''
- '%APPDATA%\agege\djdbu7l70_87qxu9zl7\6k1dc9yvf.exe'
- '<Full path to file>' 46053F055905500576056005770576055905700576056005770559054405750575054105640571056405590557056A05640568056C056B056205590544054205400542054005590561054F0561056705700532056905320535055A053D0532057...' (with hidden window)