Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '[REGKEY]' = '"%APPDATA%\[FILENAME].exe"'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '' = 'C:\'
- %WINDIR%\twunk_32.exe
- %APPDATA%\[filename].exe
- DNS ASK a.#####ng-network.to
- '%WINDIR%\twunk_32.exe'