Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Accounts Wired Hardware Initiator PC' = '<SYSTEM32>\zfaldwlib.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Transfer Alerts Profile Cache] 'ImagePath' = '<SYSTEM32>\zfaldwlib.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Transfer Alerts Profile Cache] 'Start' = '00000002'
- Windows Security Center
- '%WINDIR%\Temp\u4opk0lb7xy46tqih2j.exe' -r 24550 tcp
- '%WINDIR%\Temp\u4opk0lb3rr9wtqih2j.exe' -r 44285 tcp
- '%WINDIR%\Temp\u4opk0lbuojqjrqih2j.exe' -r 27577 tcp
- '%WINDIR%\Temp\u4opk0lb5lwhrvqih2j.exe' -r 42369 tcp
- '%WINDIR%\Temp\u4opk0lbwzb442qih2j.exe' -r 30633 tcp
- '%WINDIR%\Temp\u4opk0lbdu11wqih2j.exe' -r 34703 tcp
- '<SYSTEM32>\zrrqoogopg.exe' "<SYSTEM32>\zfaldwlib.exe"
- '<SYSTEM32>\zfaldwlib.exe'
- '%TEMP%\u4opk0lbx7v366qih2jfjydtdb.exe'
- '%WINDIR%\Temp\u4opk0lbdjx2f8qih2j.exe' -r 49024 tcp
- '%WINDIR%\Temp\u4opk0lbocogrbqih2j.exe' -r 44206 tcp
- '%WINDIR%\Temp\u4opk0lbxfpdbpqih2j.exe' -r 27554 tcp
- %WINDIR%\Temp\u4opk0lbuojqjrqih2j.exe
- %WINDIR%\Temp\u4opk0lb3rr9wtqih2j.exe
- %WINDIR%\Temp\u4opk0lbocogrbqih2j.exe
- %WINDIR%\Temp\u4opk0lbdjx2f8qih2j.exe
- %WINDIR%\Temp\u4opk0lbwzb442qih2j.exe
- %WINDIR%\Temp\u4opk0lb5lwhrvqih2j.exe
- %WINDIR%\Temp\u4opk0lb7xy46tqih2j.exe
- %WINDIR%\Temp\u4opk0lbdu11wqih2j.exe
- <SYSTEM32>\zfaldwlib.exe
- <SYSTEM32>\zrrqoogopg.exe
- <SYSTEM32>\motxknhfqxfhpv\tst
- %TEMP%\u4opk0lbx7v366qih2jfjydtdb.exe
- <SYSTEM32>\motxknhfqxfhpv\cfg
- %WINDIR%\Temp\u4opk0lbxfpdbpqih2j.exe
- <SYSTEM32>\motxknhfqxfhpv\rng
- <SYSTEM32>\motxknhfqxfhpv\run
- <SYSTEM32>\zrrqoogopg.exe
- <SYSTEM32>\zfaldwlib.exe
- %WINDIR%\Temp\u4opk0lb7xy46tqih2j.exe
- %WINDIR%\Temp\u4opk0lb3rr9wtqih2j.exe
- %WINDIR%\Temp\u4opk0lbwzb442qih2j.exe
- %WINDIR%\Temp\u4opk0lbdu11wqih2j.exe
- %WINDIR%\Temp\u4opk0lbuojqjrqih2j.exe
- %WINDIR%\Temp\u4opk0lbxfpdbpqih2j.exe
- %TEMP%\u4opk0lbx7v366qih2jfjydtdb.exe
- %WINDIR%\Temp\u4opk0lbdjx2f8qih2j.exe
- %WINDIR%\Temp\u4opk0lbocogrbqih2j.exe
- 'mi####pecial.net':80
- 'ri###nstorm.net':80
- 'do####object.net':80
- 'br###nthird.net':80
- http://mi####pecial.net/index.php
- http://ri###nstorm.net/index.php
- http://do####object.net/index.php
- http://br###nthird.net/index.php
- DNS ASK mi####pecial.net
- DNS ASK ri###nstorm.net
- DNS ASK du#####llamartinson.net
- DNS ASK do####object.net
- DNS ASK br###nthird.net
- '23#.#55.255.250':1900