Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'pbqsyctfnhj' = '"%APPDATA%\Microsoft\jxfazr.exe"'
- %APPDATA%\microsoft\jxfazr.exe
- 'ip#####.#hatismyipaddress.com':80
- http://ra###mware.bit/
- DNS ASK ip#####.#hatismyipaddress.com