Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- http://kevinhughesdesigns.com/taqp/
- http://lovenduski.com/wEsjhNd/
- http://aperfectimage.pl//HWmw/
- http://luxmedia.com.pl/portfolio/ogZ/
- http://lymanite.com/RwaYgamD/
- Copies itself to
- C:\Windows\System32\searchhost.exe
- Creates services
- HKLM\System\CurrentControlSet\services\searchhost
- Modifies several reg entries in:
- HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\
- HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
- C2 traffic tcp 8080
- Hosts
- 108.59.253.38
- 172.93.51.216
- 178.254.33.12
- 192.121.166.232
- 216.81.62.54
- 5.9.167.178
- 74.208.155.175
- 94.199.242.92
Add Comment
Please, Sign In to add comment