Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Peer Extender HomeGroup Multimedia' = '<SYSTEM32>\nrdlcvg.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Multimedia Defender Virtual Security] 'ImagePath' = '<SYSTEM32>\nrdlcvg.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Multimedia Defender Virtual Security] 'Start' = '00000002'
- '<SYSTEM32>\ebltlgmglt.exe' "<SYSTEM32>\nrdlcvg.exe"
- '<SYSTEM32>\nrdlcvg.exe'
- '%TEMP%\uviymucvafkil1ycpyc5xq.exe'
- <SYSTEM32>\ebltlgmglt.exe
- <SYSTEM32>\thhqvorcvdwj\rng
- <SYSTEM32>\thhqvorcvdwj\cli
- <SYSTEM32>\thhqvorcvdwj\tst
- %TEMP%\uviymucvafkil1ycpyc5xq.exe
- <SYSTEM32>\nrdlcvg.exe
- <SYSTEM32>\ebltlgmglt.exe
- <SYSTEM32>\nrdlcvg.exe
- %TEMP%\uviymucvafkil1ycpyc5xq.exe
- '5.##.147.5':26337
- '17#.37.2.43':44303
- '20#.#23.152.97':27682
- '41.#6.24.38':48405
- '24.##9.216.168':33794
- '71.##6.195.178':41500
- '21#.#65.0.136':35711
- '94.##1.114.138':44254
- '62.##1.108.194':20068
- '19#.#6.240.249':21875
- '18#.#50.165.14':37727
- '72.##1.207.62':22399
- '80.##1.86.158':33631
- '79.##.247.28':49038
- '88.#48.36.4':25752
- '10#.#84.231.210':47507
- '93.##7.67.155':25640
- '74.#5.64.25':22739
- '10#.#24.230.242':49777
- '95.##.58.101':23245
- '19#.#0.96.220':41884
- '22#.#1.110.45':48008
- '84.##8.128.25':27132
- '86.##5.19.130':27743
- '81.##7.50.99':52074
- '17#.#50.138.208':20422
- '15#.#82.245.137':33982
- '18#.#56.66.136':37331
- '11#.#18.187.28':42065
- '81.##4.87.112':37714
- '2.##.19.50':35833
- '10#.#02.79.27':36272
- '21#.#07.110.82':26314
- '87.##.238.184':44724
- '20#.#36.131.186':52293
- '19#.#17.67.199':45860
- '86.##5.10.227':45279
- '18#.#0.223.209':25741
- '18#.#44.105.102':28122
- '62.##.253.114':51156
- '98.##.239.20':20922
- '5.##.19.242':27426
- '41.##8.41.238':29356
- '21#.#7.168.28':52231
- '12#.#60.123.173':36805
- '10#.#46.77.146':33927
- '18#.#22.38.99':46084
- '77.##7.13.68':30018
- '10#.#4.136.243':42581
- '12#.#60.112.138':27440
- '61.##6.2.217':25840
- '20#.#7.225.58':33073
- '2.##.167.151':22437
- '78.#7.87.58':21017
- '73.##.228.84':36884
- '11#.#6.137.96':49919
- '19#.#7.134.20':44965
- '18#.#49.86.167':32097
- '79.##7.196.121':45688
- '18#.#39.175.243':37599
- '19#.#47.86.10':25432
- '31.##7.23.242':44843
- '91.##.35.122':26126
- '79.##3.139.198':21201
- '78.##5.171.93':23699
- '77.##8.205.139':22969
- '82.##7.164.91':40801
- '18#.#42.183.115':26662
- '86.##.69.232':41590