HTTP Query Text
sukipuki4mokimoki.in GET /winlocker/1.bmp HTTP/1.1
sukipuki4mokimoki.in GET /winlocker/2.bmp HTTP/1.1
Suspicious Actions Detected
Copies self to other locations
Creates autorun records
Injects code into other processes
hosting infos:
http://whois.domaintools.com/199.168.139.53