Remove 2003 Remove IPv6 Remove Programming
article thumbnail

MadoMiner Part 2 - Mask

AlienVault

During the execution of sogou.exe, the following exploits are used to install on new victims’ PCs: CVE-2017-9073, RDP vulnerability on Windows XP and Windows Server 2003. Sogou.exe is the payload that contains the CPUInfo scanner, however, it has been set to scan for IPV6 addresses. Folder: C:%Program Files%Windowsd.

Malware 40