Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Defragmenter Portable DNS Net.Tcp' = '<SYSTEM32>\imuliqjugbeo.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\IPsec Profile Performance] 'ImagePath' = '<SYSTEM32>\imuliqjugbeo.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\IPsec Profile Performance] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\sihcojtji.exe' "<SYSTEM32>\imuliqjugbeo.exe"
- '%WINDIR%\Temp\wuxqckr5bfvgyj3ns.exe' -r 27521 tcp
- '%TEMP%\wuxqckrch2iypj3nssvzliv.exe'
- '<SYSTEM32>\imuliqjugbeo.exe'
- <SYSTEM32>\ahvoyho\run
- <SYSTEM32>\ahvoyho\cli
- %WINDIR%\Temp\wuxqckr5bfvgyj3ns.exe
- <SYSTEM32>\ahvoyho\cfg
- <SYSTEM32>\ahvoyho\rng
- %TEMP%\wuxqckrch2iypj3nssvzliv.exe
- <SYSTEM32>\ahvoyho\tst
- <SYSTEM32>\sihcojtji.exe
- <SYSTEM32>\imuliqjugbeo.exe
- <SYSTEM32>\sihcojtji.exe
- <SYSTEM32>\imuliqjugbeo.exe
- %WINDIR%\Temp\wuxqckr5bfvgyj3ns.exe
- %TEMP%\wuxqckrch2iypj3nssvzliv.exe
- '93.##3.140.196':29863
- '17#.#6.177.19':25630
- '74.#5.64.25':22739
- '2.##.142.171':22437
- '86.##.197.245':25978
- '11#.#18.187.28':42065
- '86.##5.146.126':30982
- '87.##.64.127':30018
- '89.##7.252.28':48576
- '5.##.138.37':35833
- '83.##0.203.141':26734
- '10#.#55.232.115':41710
- '88.#48.36.4':25752
- '87.##.238.184':44724
- '18#.#44.51.96':28122
- '81.#34.1.9':45279
- '61.##6.2.217':25840
- '94.##.200.147':41925
- '37.##2.247.223':22969
- '12#.#60.123.173':36805
- '18#.#5.73.246':27577
- '90.##.215.140':49291
- '89.##.163.63':50096
- '19#.#6.160.211':34550
- '18#.#5.59.224':27426
- '86.##7.17.15':45688
- '84.#4.45.89':49727
- '75.##.211.234':31064
- '10#.#9.205.40':22972
- '2.##.162.11':35196
- '93.##6.144.177':30459
- '89.##8.217.21':21212
- '17#.#50.138.208':20422
- '17#.37.2.43':44303
- '94.##5.160.53':36355
- '20#.#23.152.97':27682
- '79.##2.80.180':33634
- '72.#32.76.8':35779
- '86.##.69.106':41590
- '10#.#02.79.27':36272
- '50.##0.231.206':50776
- '10#.#89.140.68':41209
- '2.##.156.78':35711
- '18#.#20.35.137':43621
- '87.#7.245.8':33631
- '98.##.222.153':20922
- '21#.#65.4.137':26502
- '10#.#5.150.243':24830
- '21#.37.5.79':49380
- '89.##0.101.64':30714
- '89.##0.20.12':46689
- '18#.#8.118.52':23245
- '85.#4.86.41':51481
- '70.#12.6.44':41500
- '78.##1.130.191':23699
- '79.##8.132.213':22773
- '46.##.134.22':36034
- '10#.#9.142.6':20155
- '2.##.137.65':27577
- '81.##.222.124':31810
- '84.##8.128.25':27132
- '94.##1.114.138':44254
- '18#.2.10.6':44843
- '18#.#6.131.45':28990
- '23#.#55.255.250':1900