Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Propagation Assistant VC Machine' = '<SYSTEM32>\yjliwafeakm.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Time Visual Biometric Files CNG] 'ImagePath' = '<SYSTEM32>\yjliwafeakm.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Time Visual Biometric Files CNG] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\pxnshwqqem.exe' "<SYSTEM32>\yjliwafeakm.exe"
- '%WINDIR%\Temp\ddwywh2nkzrtbt.exe' -r 26755 tcp
- '%TEMP%\ddwywh2iafrtbtgapwtf.exe'
- '<SYSTEM32>\yjliwafeakm.exe'
- <SYSTEM32>\yxajmoeadcn\run
- <SYSTEM32>\yxajmoeadcn\rng
- %WINDIR%\Temp\ddwywh2nkzrtbt.exe
- <SYSTEM32>\yxajmoeadcn\cfg
- <SYSTEM32>\pxnshwqqem.exe
- %TEMP%\ddwywh2iafrtbtgapwtf.exe
- <SYSTEM32>\yxajmoeadcn\tst
- <SYSTEM32>\yjliwafeakm.exe
- <SYSTEM32>\yxajmoeadcn\etc
- <SYSTEM32>\pxnshwqqem.exe
- <SYSTEM32>\yjliwafeakm.exe
- %WINDIR%\Temp\ddwywh2nkzrtbt.exe
- <DRIVERS>\etc\hosts
- %TEMP%\ddwywh2iafrtbtgapwtf.exe
- 'ta###aunt.net':80
- 'le###unt.net':80
- 'fe###ont.net':80
- 'we###ont.net':80
- 'ta###great.net':80
- 'le###reat.net':80
- 'ta###scene.net':80
- 'le###cene.net':80
- 'we###reat.net':80
- 'li###ont.net':80
- 'fe###unt.net':80
- 'li###reat.net':80
- 'th###dont.net':80
- 'we###cene.net':80
- 'fe###reat.net':80
- 'we###unt.net':80
- 'fe###cene.net':80
- 'ta###dont.net':80
- 'no###reat.net':80
- 'no###ont.net':80
- 'no###unt.net':80
- 'no###cene.net':80
- 'ri###cene.net':80
- 'fa###scene.net':80
- 'ri###unt.net':80
- 'fa###aunt.net':80
- 'ca###ont.net':80
- 'ca###unt.net':80
- 'po###scene.net':80
- 'le###ont.net':80
- 'po###aunt.net':80
- 'ca###reat.net':80
- 'po###dont.net':80
- 'ca###cene.net':80
- 'po###great.net':80
- 'we###ight.net':80
- 'no###ight.net':80
- 'we###ive.net':80
- 'no###ive.net':80
- 'fa###voice.net':80
- 'ri###ive.net':80
- 'we###hey.net':80
- 'ri###oice.net':80
- 'no###oice.net':80
- 'be##lxc.com':80
- 'de###lxc.com':80
- 'ri###nstorm.net':80
- 'af###sllc.com':80
- 'li###hey.net':80
- 'we###oice.net':80
- 'li###ight.net':80
- 'no###hey.net':80
- 'fa###five.net':80
- 'fi###dont.net':80
- 'th###aunt.net':80
- 'fi###great.net':80
- 'so###dont.net':80
- 'li###cene.net':80
- 'th###great.net':80
- 'li###unt.net':80
- 'th###scene.net':80
- 'so###great.net':80
- 'ri###hey.net':80
- 'fa###they.net':80
- 'ri###ight.net':80
- 'fa###eight.net':80
- 'so###scene.net':80
- 'fi###scene.net':80
- 'so###aunt.net':80
- 'fi###aunt.net':80
- http://ta###aunt.net/index.php
- http://le###unt.net/index.php
- http://fe###ont.net/index.php
- http://we###ont.net/index.php
- http://ta###great.net/index.php
- http://le###reat.net/index.php
- http://ta###scene.net/index.php
- http://le###cene.net/index.php
- http://we###reat.net/index.php
- http://li###ont.net/index.php
- http://fe###unt.net/index.php
- http://li###reat.net/index.php
- http://th###dont.net/index.php
- http://we###cene.net/index.php
- http://fe###reat.net/index.php
- http://we###unt.net/index.php
- http://fe###cene.net/index.php
- http://ta###dont.net/index.php
- http://no###reat.net/index.php
- http://no###ont.net/index.php
- http://no###unt.net/index.php
- http://no###cene.net/index.php
- http://ri###cene.net/index.php
- http://fa###scene.net/index.php
- http://ri###unt.net/index.php
- http://fa###aunt.net/index.php
- http://ca###ont.net/index.php
- http://ca###unt.net/index.php
- http://po###scene.net/index.php
- http://le###ont.net/index.php
- http://po###aunt.net/index.php
- http://ca###reat.net/index.php
- http://po###dont.net/index.php
- http://ca###cene.net/index.php
- http://po###great.net/index.php
- http://we###ight.net/index.php
- http://no###ight.net/index.php
- http://we###ive.net/index.php
- http://no###ive.net/index.php
- http://fa###voice.net/index.php
- http://ri###ive.net/index.php
- http://we###hey.net/index.php
- http://ri###oice.net/index.php
- http://no###oice.net/index.php
- http://be##lxc.com/index.php
- http://de###lxc.com/index.php
- http://ri###nstorm.net/index.php
- http://af###sllc.com/index.php
- http://li###hey.net/index.php
- http://we###oice.net/index.php
- http://li###ight.net/index.php
- http://no###hey.net/index.php
- http://fa###five.net/index.php
- http://fi###dont.net/index.php
- http://th###aunt.net/index.php
- http://fi###great.net/index.php
- http://so###dont.net/index.php
- http://li###cene.net/index.php
- http://th###great.net/index.php
- http://li###unt.net/index.php
- http://th###scene.net/index.php
- http://so###great.net/index.php
- http://ri###hey.net/index.php
- http://fa###they.net/index.php
- http://ri###ight.net/index.php
- http://fa###eight.net/index.php
- http://so###scene.net/index.php
- http://fi###scene.net/index.php
- http://so###aunt.net/index.php
- http://fi###aunt.net/index.php
- DNS ASK ta###aunt.net
- DNS ASK le###unt.net
- DNS ASK fe###ont.net
- DNS ASK we###ont.net
- DNS ASK ta###scene.net
- DNS ASK le###reat.net
- DNS ASK ta###dont.net
- DNS ASK le###cene.net
- DNS ASK ta###great.net
- DNS ASK li###ont.net
- DNS ASK fe###unt.net
- DNS ASK li###reat.net
- DNS ASK th###dont.net
- DNS ASK we###unt.net
- DNS ASK fe###reat.net
- DNS ASK we###reat.net
- DNS ASK fe###cene.net
- DNS ASK we###cene.net
- DNS ASK no###reat.net
- DNS ASK no###ont.net
- DNS ASK no###unt.net
- DNS ASK no###cene.net
- DNS ASK ri###unt.net
- DNS ASK fa###scene.net
- DNS ASK ri###reat.net
- DNS ASK fa###aunt.net
- DNS ASK ri###cene.net
- DNS ASK ca###unt.net
- DNS ASK po###scene.net
- DNS ASK le###ont.net
- DNS ASK po###aunt.net
- DNS ASK ca###cene.net
- DNS ASK po###dont.net
- DNS ASK ca###ont.net
- DNS ASK po###great.net
- DNS ASK ca###reat.net
- DNS ASK we###ight.net
- DNS ASK no###ight.net
- DNS ASK we###ive.net
- DNS ASK no###ive.net
- DNS ASK fa###voice.net
- DNS ASK ri###ive.net
- DNS ASK we###hey.net
- DNS ASK ri###oice.net
- DNS ASK no###oice.net
- DNS ASK be##lxc.com
- DNS ASK de###lxc.com
- DNS ASK ri###nstorm.net
- DNS ASK af###sllc.com
- DNS ASK li###hey.net
- DNS ASK we###oice.net
- DNS ASK li###ight.net
- DNS ASK no###hey.net
- DNS ASK fa###five.net
- DNS ASK fi###dont.net
- DNS ASK th###aunt.net
- DNS ASK fi###great.net
- DNS ASK so###dont.net
- DNS ASK li###cene.net
- DNS ASK th###great.net
- DNS ASK li###unt.net
- DNS ASK th###scene.net
- DNS ASK so###great.net
- DNS ASK ri###hey.net
- DNS ASK fa###they.net
- DNS ASK ri###ight.net
- DNS ASK fa###eight.net
- DNS ASK so###scene.net
- DNS ASK fi###scene.net
- DNS ASK so###aunt.net
- DNS ASK fi###aunt.net
- '23#.#55.255.250':1900