Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%APPDATA%\wintemp\cKTweVURapZP.exe",explorer.exe'
- %APPDATA%\wintemp\cktwevurapzp.exe
- %TEMP%\op8zdboyqgpbdcnl.jpg
- %APPDATA%\wintemp\cktwevurapzp.exe
- 'pa###bin.com':443
- 'localhost':0
- 'pa###bin.com':443
- DNS ASK pa###bin.com