Home Malware Programs Browser Hijackers 123.sogou.com

123.sogou.com

Posted: September 28, 2015

Threat Metric

Ranking: 1,174
Threat Level: 5/10
Infected PCs: 138,252
First Seen: September 28, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without path123.sogou[1].xmlHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\SogouSoftwareSOFTWARE\Classes\SogouSoftwareSOFTWARE\Microsoft\Internet Explorer\DOMStorage\123.sogou.comSOFTWARE\Microsoft\Internet Explorer\DOMStorage\sogou.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\123.sogou.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sogou.comSOFTWARE\Microsoft\Tracing\SogouSoftware_RASAPI32SOFTWARE\Microsoft\Tracing\SogouSoftware_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Run\SogouSoftwareAutoRunSOFTWARE\MozillaPlugins\@sogou.com/SGDownloadPluginSOFTWARE\SogouSoftwareHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SogouSoftware

Additional Information

The following directories were created:
%PROGRAMFILES%\SogouSoftware%PROGRAMFILES(x86)%\SogouSoftware%USERPROFILE%\AppData\LocalLow\SogouSoftware
The following URL's were detected:
/123.sogou.com
Loading...