Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Parental Intelligent Event Filtering' = '<SYSTEM32>\lwkzvmxgeys.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Manager Auto-Discovery Spooler] 'ImagePath' = '<SYSTEM32>\lwkzvmxgeys.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Manager Auto-Discovery Spooler] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\jomoisw.exe' "<SYSTEM32>\lwkzvmxgeys.exe"
- '%WINDIR%\Temp\aw2ggjhx2bmr5gncp.exe' -r 28579 tcp
- '%TEMP%\aw2ggjhxd3ue68ncpk7vywp.exe'
- '<SYSTEM32>\lwkzvmxgeys.exe'
- <SYSTEM32>\kfkrtojdyvfhj\run
- <SYSTEM32>\kfkrtojdyvfhj\cli
- %WINDIR%\Temp\aw2ggjhx2bmr5gncp.exe
- <SYSTEM32>\kfkrtojdyvfhj\cfg
- <SYSTEM32>\kfkrtojdyvfhj\rng
- %TEMP%\aw2ggjhxd3ue68ncpk7vywp.exe
- <SYSTEM32>\kfkrtojdyvfhj\tst
- <SYSTEM32>\jomoisw.exe
- <SYSTEM32>\lwkzvmxgeys.exe
- <SYSTEM32>\jomoisw.exe
- <SYSTEM32>\lwkzvmxgeys.exe
- %WINDIR%\Temp\aw2ggjhx2bmr5gncp.exe
- %TEMP%\aw2ggjhxd3ue68ncpk7vywp.exe
- '17#.#50.138.208':20422
- '86.#8.4.250':31237
- '21#.#52.20.92':23212
- '2.##.140.53':27577
- '18#.#5.73.246':27577
- '79.##7.186.42':45688
- '21#.37.5.79':49380
- '18#.#6.131.45':28990
- '18#.2.10.6':44843
- '85.#4.86.41':51481
- '95.##.197.175':33733
- '18#.#44.86.207':28122
- '18#.#49.135.207':22714
- '10#.#4.195.221':33634
- '90.##.215.140':49291
- '18#.#73.89.80':24148
- '2.##.143.246':41590
- '17#.37.2.43':44303
- '2.##.30.56':26734
- '2.##.170.96':35711
- '89.##6.28.221':41556
- '84.##7.100.62':48747
- '85.##.173.200':31810
- '20#.#7.162.226':52230
- '24.#7.4.91':35877
- '97.##.251.170':31083
- '79.##8.132.213':22773
- '86.##.197.245':25978
- '10#.#5.150.243':24830
- '37.##2.247.223':22969
- '87.#7.245.8':33631
- '2.##.162.11':35196
- '74.#5.64.25':22739
- '21#.#65.121.250':26502
- '89.##0.20.12':46689
- '31.##.106.150':25448
- '81.#34.1.9':45279
- '11#.#18.187.28':42065
- '89.##0.101.64':30714
- '18#.#5.59.224':27426
- '12#.#38.112.130':22972
- '95.#6.10.47':48576
- '2.##.142.171':22437
- '46.##6.39.60':21212
- '21#.#54.135.76':38573
- '5.##.138.37':35833
- '85.##0.201.14':29863
- '5.###.189.191':51519
- '85.##6.62.161':29923
- '84.#4.45.89':49727
- '46.##.134.22':36034
- '41.##0.16.173':34550
- '17#.#6.177.19':25630
- '10#.#49.241.50':30982
- '70.##.130.190':20735
- '89.##.163.63':50096
- '84.##2.229.165':29052
- '93.##6.144.177':30459
- '18#.#52.148.185':41862
- '94.##1.114.138':44254
- '10#.#86.116.127':25121
- '83.#0.43.93':34601
- '75.##.211.234':31064
- '79.##3.168.30':34665
- '88.#48.36.4':25752
- '10#.#02.79.27':36272
- '72.#32.76.8':35779
- '10#.#9.142.6':20155
- '94.##5.161.141':36355
- '10#.#22.111.221':45678
- '70.##4.102.29':41500
- '87.##2.107.169':41925
- '98.##.221.92':20922
- '10#.#55.232.115':41710
- '21#.#83.203.135':38827
- '21#.#37.115.71':51641
- '78.##1.130.191':23699
- '77.##6.220.10':30018
- '12#.#60.123.173':36805
- '95.##.67.245':23245
- '50.##0.231.206':50776
- '83.##0.155.60':49499
- '20#.#23.152.97':27682
- '84.##8.128.25':27132
- '10#.#89.140.68':41209
- '23#.#55.255.250':1900