Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Filtering Machine Level Now' = '<SYSTEM32>\bsxtmqhgwg.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\WMI Files Windows Credential] 'ImagePath' = '<SYSTEM32>\bsxtmqhgwg.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\WMI Files Windows Credential] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\kzradjvyj.exe' "<SYSTEM32>\bsxtmqhgwg.exe"
- '%WINDIR%\Temp\akuulrg2z0vlvxt.exe' -r 34765 tcp
- '%TEMP%\akuulrg2k2olvxtywelvil.exe'
- '<SYSTEM32>\bsxtmqhgwg.exe'
- <SYSTEM32>\ddabnkfdmvffs\run
- <SYSTEM32>\ddabnkfdmvffs\rng
- %WINDIR%\Temp\akuulrg2z0vlvxt.exe
- <SYSTEM32>\ddabnkfdmvffs\cfg
- <SYSTEM32>\kzradjvyj.exe
- %TEMP%\akuulrg2k2olvxtywelvil.exe
- <SYSTEM32>\ddabnkfdmvffs\tst
- <SYSTEM32>\bsxtmqhgwg.exe
- <SYSTEM32>\ddabnkfdmvffs\etc
- <SYSTEM32>\kzradjvyj.exe
- <SYSTEM32>\bsxtmqhgwg.exe
- %WINDIR%\Temp\akuulrg2z0vlvxt.exe
- <DRIVERS>\etc\hosts
- %TEMP%\akuulrg2k2olvxtywelvil.exe
- 'so###name.net':80
- 'ar###guide.net':80
- 'so###guide.net':80
- 'ar###name.net':80
- 'th###nly.net':80
- 'ar###half.net':80
- 'so###half.net':80
- 'up###ame.net':80
- 'wh###name.net':80
- 'up###uide.net':80
- 'wh###half.net':80
- 'ar###late.net':80
- 'so###late.net':80
- 'up###alf.net':80
- 'fa###olor.net':80
- 'wa###only.net':80
- 'fa###nly.net':80
- 'de###lxc.com':80
- 'ri###nstorm.net':80
- 'af###sllc.com':80
- 'be##lxc.com':80
- 'dr###color.net':80
- 'th###olor.net':80
- 'dr###only.net':80
- 'th###igh.net':80
- 'dr###feel.net':80
- 'th###eel.net':80
- 'dr###high.net':80
- http://so###name.net/index.php
- http://ar###guide.net/index.php
- http://so###guide.net/index.php
- http://ar###name.net/index.php
- http://th###nly.net/index.php
- http://ar###half.net/index.php
- http://so###half.net/index.php
- http://up###ame.net/index.php
- http://wh###name.net/index.php
- http://up###uide.net/index.php
- http://wh###half.net/index.php
- http://ar###late.net/index.php
- http://so###late.net/index.php
- http://up###alf.net/index.php
- http://fa###olor.net/index.php
- http://wa###only.net/index.php
- http://fa###nly.net/index.php
- http://de###lxc.com/index.php
- http://ri###nstorm.net/index.php
- http://af###sllc.com/index.php
- http://be##lxc.com/index.php
- http://dr###color.net/index.php
- http://th###olor.net/index.php
- http://dr###only.net/index.php
- http://th###igh.net/index.php
- http://dr###feel.net/index.php
- http://th###eel.net/index.php
- http://dr###high.net/index.php
- DNS ASK so###name.net
- DNS ASK ar###guide.net
- DNS ASK so###guide.net
- DNS ASK ar###name.net
- DNS ASK th###nly.net
- DNS ASK ar###half.net
- DNS ASK so###half.net
- DNS ASK up###ame.net
- DNS ASK wh###name.net
- DNS ASK up###uide.net
- DNS ASK wh###half.net
- DNS ASK ar###late.net
- DNS ASK so###late.net
- DNS ASK up###alf.net
- DNS ASK dr###only.net
- DNS ASK de###lxc.com
- DNS ASK fa###olor.net
- DNS ASK wa###only.net
- DNS ASK ri###nstorm.net
- DNS ASK af###sllc.com
- DNS ASK be##lxc.com
- DNS ASK fa###nly.net
- DNS ASK th###igh.net
- DNS ASK dr###color.net
- DNS ASK th###olor.net
- DNS ASK dr###feel.net
- DNS ASK th###eel.net
- DNS ASK dr###high.net
- '23#.#55.255.250':1900