Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WinSvcHost' = '%APPDATA%\Microsoft\WinSvc\svchost.exe'
- %APPDATA%\microsoft\winsvc\svchost.exe
- %APPDATA%\microsoft\winsvc\svchost.exe
- %TEMP%\0000ec0d.tmp
- from <Full path to file> to %TEMP%\0000ec0d.tmp
- '19#.#69.194.13':5000
- http://19#.##9.194.13:5000/s/gate via 19#.#69.194.13
- http://19#.##9.194.13:5000/api/beacon via 19#.#69.194.13