Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Group Drive Foundation ActiveX Support Logon' = '<SYSTEM32>\prmmnpylv.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Management Resource Host WLAN] 'ImagePath' = '<SYSTEM32>\prmmnpylv.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Management Resource Host WLAN] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\jtdasfearc.exe' "<SYSTEM32>\prmmnpylv.exe"
- '%WINDIR%\Temp\uaz6qbl30kubo.exe' -r 22058 tcp
- '%TEMP%\uaz6qbl2q2tbospieem.exe'
- '<SYSTEM32>\prmmnpylv.exe'
- <SYSTEM32>\fvcvwbcmmpv\run
- <SYSTEM32>\fvcvwbcmmpv\rng
- %WINDIR%\Temp\uaz6qbl30kubo.exe
- <SYSTEM32>\fvcvwbcmmpv\cfg
- <SYSTEM32>\jtdasfearc.exe
- %TEMP%\uaz6qbl2q2tbospieem.exe
- <SYSTEM32>\fvcvwbcmmpv\tst
- <SYSTEM32>\prmmnpylv.exe
- <SYSTEM32>\fvcvwbcmmpv\etc
- <SYSTEM32>\jtdasfearc.exe
- <SYSTEM32>\prmmnpylv.exe
- %WINDIR%\Temp\uaz6qbl30kubo.exe
- <DRIVERS>\etc\hosts
- %TEMP%\uaz6qbl2q2tbospieem.exe
- 'fr###ypaid.net':80
- 'pu###ugust.net':80
- 'fr####august.net':80
- 'pu###aid.net':80
- 'de###orn.net':80
- 'pu###loth.net':80
- 'fr###ycloth.net':80
- 'pu###orn.net':80
- 'de####erpaid.net':80
- 'al###august.net':80
- 'de####eraugust.net':80
- 'al###paid.net':80
- 'fr###yborn.net':80
- 'al###cloth.net':80
- 'de####ercloth.net':80
- 'sh###born.net':80
- 'ti###aid.net':80
- 'mo###august.net':80
- 'ti###ugust.net':80
- 'de###lxc.com':80
- 'ri###nstorm.net':80
- 'af###sllc.com':80
- 'be##lxc.com':80
- 'mo###born.net':80
- 'de###aid.net':80
- 'sh###august.net':80
- 'de###ugust.net':80
- 'sh###paid.net':80
- 'ti###orn.net':80
- 'sh###cloth.net':80
- 'de###loth.net':80
- http://fr###ypaid.net/index.php
- http://pu###ugust.net/index.php
- http://fr####august.net/index.php
- http://pu###aid.net/index.php
- http://de###orn.net/index.php
- http://pu###loth.net/index.php
- http://fr###ycloth.net/index.php
- http://pu###orn.net/index.php
- http://de####erpaid.net/index.php
- http://al###august.net/index.php
- http://de####eraugust.net/index.php
- http://al###paid.net/index.php
- http://fr###yborn.net/index.php
- http://al###cloth.net/index.php
- http://de####ercloth.net/index.php
- http://sh###born.net/index.php
- http://ti###aid.net/index.php
- http://mo###august.net/index.php
- http://ti###ugust.net/index.php
- http://de###lxc.com/index.php
- http://ri###nstorm.net/index.php
- http://af###sllc.com/index.php
- http://be##lxc.com/index.php
- http://mo###born.net/index.php
- http://de###aid.net/index.php
- http://sh###august.net/index.php
- http://de###ugust.net/index.php
- http://sh###paid.net/index.php
- http://ti###orn.net/index.php
- http://sh###cloth.net/index.php
- http://de###loth.net/index.php
- DNS ASK fr###ypaid.net
- DNS ASK pu###aid.net
- DNS ASK fr####august.net
- DNS ASK pu###ugust.net
- DNS ASK de###orn.net
- DNS ASK sh###born.net
- DNS ASK fr###ycloth.net
- DNS ASK pu###loth.net
- DNS ASK de####erpaid.net
- DNS ASK al###paid.net
- DNS ASK de####eraugust.net
- DNS ASK al###august.net
- DNS ASK fr###yborn.net
- DNS ASK pu###orn.net
- DNS ASK de####ercloth.net
- DNS ASK al###cloth.net
- DNS ASK ti###aid.net
- DNS ASK mo###august.net
- DNS ASK ti###ugust.net
- DNS ASK de###lxc.com
- DNS ASK ri###nstorm.net
- DNS ASK af###sllc.com
- DNS ASK be##lxc.com
- DNS ASK mo###born.net
- DNS ASK de###aid.net
- DNS ASK sh###august.net
- DNS ASK de###ugust.net
- DNS ASK sh###paid.net
- DNS ASK ti###orn.net
- DNS ASK sh###cloth.net
- DNS ASK de###loth.net
- '23#.#55.255.250':1900