Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'PC Peer Removal Wired TCP/IP' = '<SYSTEM32>\snjlnglygbuu.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Builder Transaction SPP Registrar] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\kmlnqcdmned.exe' "<SYSTEM32>\snjlnglygbuu.exe"
- '%WINDIR%\Temp\wmxdvx46uznpz.exe' -r 34527 tcp
- '%TEMP%\wmxdvx3sgbnpznnzfwtr.exe'
- '<SYSTEM32>\snjlnglygbuu.exe'
- <SYSTEM32>\sawxevpr\run
- <SYSTEM32>\sawxevpr\rng
- %WINDIR%\Temp\wmxdvx46uznpz.exe
- <SYSTEM32>\sawxevpr\cfg
- <SYSTEM32>\kmlnqcdmned.exe
- %TEMP%\wmxdvx3sgbnpznnzfwtr.exe
- <SYSTEM32>\sawxevpr\tst
- <SYSTEM32>\snjlnglygbuu.exe
- <SYSTEM32>\sawxevpr\etc
- <SYSTEM32>\kmlnqcdmned.exe
- <SYSTEM32>\snjlnglygbuu.exe
- %WINDIR%\Temp\wmxdvx46uznpz.exe
- <DRIVERS>\etc\hosts
- %TEMP%\wmxdvx3sgbnpznnzfwtr.exe
- 'ab###est.net':80
- 'kn###pen.net':80
- 'ab###pen.net':80
- 'kn###est.net':80
- 'ab###oat.net':80
- 'kn###ress.net':80
- 'ab###ress.net':80
- 'pi###oat.net':80
- 'so###est.net':80
- 'pi###pen.net':80
- 'so###pen.net':80
- 'pi###est.net':80
- 'so###oat.net':80
- 'pi###ress.net':80
- 'so###ress.net':80
- 'kn###oat.net':80
- 'lo###egan.net':80
- 'th###kind.net':80
- 'lo###ind.net':80
- 'de###lxc.com':80
- 'ri###nstorm.net':80
- 'af###sllc.com':80
- 'be##lxc.com':80
- 'dr###wild.net':80
- 'wi###egan.net':80
- 'dr###kind.net':80
- 'wi###ind.net':80
- 'dr###began.net':80
- 'wi###ild.net':80
- 'dr###june.net':80
- 'wi###une.net':80
- http://ab###est.net/index.php
- http://kn###pen.net/index.php
- http://ab###pen.net/index.php
- http://kn###est.net/index.php
- http://ab###oat.net/index.php
- http://kn###ress.net/index.php
- http://ab###ress.net/index.php
- http://pi###oat.net/index.php
- http://so###est.net/index.php
- http://pi###pen.net/index.php
- http://so###pen.net/index.php
- http://pi###est.net/index.php
- http://so###oat.net/index.php
- http://pi###ress.net/index.php
- http://so###ress.net/index.php
- http://kn###oat.net/index.php
- http://lo###egan.net/index.php
- http://th###kind.net/index.php
- http://lo###ind.net/index.php
- http://de###lxc.com/index.php
- http://ri###nstorm.net/index.php
- http://af###sllc.com/index.php
- http://be##lxc.com/index.php
- http://dr###wild.net/index.php
- http://wi###egan.net/index.php
- http://dr###kind.net/index.php
- http://wi###ind.net/index.php
- http://dr###began.net/index.php
- http://wi###ild.net/index.php
- http://dr###june.net/index.php
- http://wi###une.net/index.php
- DNS ASK kn###pen.net
- DNS ASK ab###est.net
- DNS ASK pi###oat.net
- DNS ASK ab###pen.net
- DNS ASK kn###ress.net
- DNS ASK ab###oat.net
- DNS ASK kn###est.net
- DNS ASK ab###ress.net
- DNS ASK pi###pen.net
- DNS ASK so###est.net
- DNS ASK ro###oat.net
- DNS ASK so###pen.net
- DNS ASK pi###ress.net
- DNS ASK so###oat.net
- DNS ASK pi###est.net
- DNS ASK so###ress.net
- DNS ASK kn###oat.net
- DNS ASK lo###egan.net
- DNS ASK th###kind.net
- DNS ASK lo###ind.net
- DNS ASK de###lxc.com
- DNS ASK ri###nstorm.net
- DNS ASK af###sllc.com
- DNS ASK be##lxc.com
- DNS ASK dr###wild.net
- DNS ASK wi###egan.net
- DNS ASK dr###kind.net
- DNS ASK wi###ind.net
- DNS ASK dr###began.net
- DNS ASK wi###ild.net
- DNS ASK dr###june.net
- DNS ASK wi###une.net
- '23#.#55.255.250':1900