Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'User-mode Time Redirector CNG Multimedia' = '<SYSTEM32>\jessxcc.exe'
- Windows Security Center
- <SYSTEM32>\qocpyiexs\run
- <SYSTEM32>\qocpyiexs\cli
- %TEMP%\wnewyihorq0krtvi9e.exe
- <SYSTEM32>\qocpyiexs\cfg
- <SYSTEM32>\qocpyiexs\rng
- %TEMP%\wnewyiho95a3m7vi9ecc2n5km0.exe
- <SYSTEM32>\qocpyiexs\tst
- <SYSTEM32>\pfltgrsak.exe
- <SYSTEM32>\jessxcc.exe
- <SYSTEM32>\pfltgrsak.exe
- <SYSTEM32>\jessxcc.exe
- %TEMP%\wnewyiho95a3m7vi9ecc2n5km0.exe
- '71.##2.212.226':26466
- '37.##2.223.103':22969
- '18#.#07.197.116':24498
- '19#.#7.134.20':44965
- '18#.#49.88.79':32097
- '22#.#1.110.45':48008
- '79.##1.239.74':42581
- '17#.#50.138.208':20422
- '19#.#45.26.50':31421
- '20#.#23.152.97':27682
- '21#.#7.168.28':52231
- '93.##7.67.155':25640
- '2.##.156.247':35711
- '83.##0.248.151':23268
- '20#.#11.99.94':37369
- '18#.#22.45.37':46084
- '79.##.202.44':23699
- '86.##.69.232':41590
- '19#.#0.41.168':43832
- '11#.#42.143.147':31567
- '20#.#71.22.221':32994
- '92.##7.45.207':21921
- '77.##7.13.68':30018
- '17#.37.2.43':44303
- '12#.#60.123.173':36805
- '77.##.186.45':43519
- '19#.#62.66.148':52345
- '92.##7.78.237':47427
- '80.##1.86.158':33631
- '61.##6.2.217':25840
- '87.##.238.184':44724
- '94.##1.114.138':44254
- '10#.#56.58.121':45860
- '84.##2.194.230':27426
- '81.##4.87.112':37714
- '18#.#55.19.91':30767
- '20#.#70.207.211':37727
- '74.#5.64.25':22739
- '88.#48.36.4':25752
- '86.##5.19.130':27743
- '81.##7.50.99':52074
- '15#.#82.245.137':33982
- '98.##0.152.114':48605
- '10#.#46.77.146':33927
- '2.##.19.50':35833
- '87.##6.160.36':41347
- '79.##7.196.121':45688
- '18#.#72.215.47':51612
- '19#.#54.74.242':31770
- '84.##8.130.85':27132
- '67.##.64.252':27314
- '2.##.167.151':22437
- '20#.#93.204.80':37195
- '62.##1.108.194':20068
- '18#.#55.237.75':28122
- '80.#4.199.6':49579
- '11#.#6.137.96':49919
- '19#.#0.96.220':41884
- '20#.#7.225.58':33073
- '19#.#47.86.10':25432
- '18#.2.4.92':44843
- '19#.74.51.3':32904
- '82.##7.164.91':40801
- '69.##1.140.58':36102
- '5.##.147.158':23144
- '18#.#5.131.224':26337
- '10#.#67.38.149':20466
- '95.##7.243.188':49038
- '12#.#60.112.138':27440
- '88.##.203.114':40413
- '11#.#18.187.28':42065
- '10#.#02.79.27':36272
- '70.##5.4.143':41500
- '18#.#45.182.189':37331
- '5.#.166.192':41199
- '41.#6.20.41':48405
- '18#.#0.220.30':25741
- '24.##1.42.214':47782
- '20#.#36.131.186':52293
- '72.#9.59.91':23362
- '10#.#25.112.152':47507
- '10#.#28.239.221':49777
- '72.##1.47.203':22399
- '10#.#2.195.20':39160
- '18#.#39.124.68':37599
- '86.##5.219.12':21375
- '79.##5.10.236':21201
- '18#.#42.107.86':26662
- '85.##.122.169':40540
- '17#.#40.117.149':27603
- '86.##5.10.227':45279
- '62.##.253.114':51156
- '24.##9.216.168':33794
- '91.##.35.122':26126
- '21#.#19.80.21':36542
- '18#.#55.161.27':20052
- '23#.#55.255.250':1900
- '<SYSTEM32>\pfltgrsak.exe' "<SYSTEM32>\jessxcc.exe"
- '%TEMP%\wnewyihorq0krtvi9e.exe' -r 51324 tcp
- '%TEMP%\wnewyiho95a3m7vi9ecc2n5km0.exe'
- '<SYSTEM32>\jessxcc.exe'