Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SEJOKAOI5S' = '"%APPDATA%\BzcPYMcTBP.js"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\bzcpymctbp.js
- %APPDATA%\bzcpymctbp.js
- '19#.5.98.75':4532
- http://19#.#.98.75:4532/Vre via 19#.5.98.75
- DNS ASK ja####inns.duia.ro
- '<SYSTEM32>\wscript.exe' //B "%APPDATA%\BzcPYMcTBP.js"