Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Ommycm yuyiasak4' = '%ProgramFiles(x86)%\Skaklqswwusss.exe'
- %ProgramFiles(x86)%\skaklqswwusss.exe
- C:\2866.vbs
- C:\2866.vbs
- from <Full path to file> to %ProgramFiles(x86)%\skaklqswwusss.exe
- 'li####zz.vicp.cc':32194
- DNS ASK li####zz.vicp.cc
- '%ProgramFiles(x86)%\skaklqswwusss.exe'
- '%WINDIR%\syswow64\wscript.exe' "C:\2866.vbs"
- '%WINDIR%\syswow64\wscript.exe' "C:\2866.vbs"' (with hidden window)