Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Connections Encrypting Collector AutoConnect' = 'C:\vlzppcz\ukkbraqagw.exe'
- 'C:\vlzppcz\iqvnahz.exe' "c:\vlzppcz\ukkbraqagw.exe"
- 'C:\vlzppcz\ukkbraqagw.exe'
- 'C:\vlzppcz\tuyiy3wp3n0uiaaygb8we.exe'
- C:\vlzppcz\ukkbraqagw.exe
- C:\vlzppcz\iqvnahz.exe
- C:\vlzppcz\fcjqcs
- %WINDIR%\vlzppcz\axbqmfibyjg
- C:\vlzppcz\axbqmfibyjg
- C:\vlzppcz\tuyiy3wp3n0uiaaygb8we.exe
- C:\vlzppcz\iqvnahz.exe
- C:\vlzppcz\ukkbraqagw.exe
- C:\vlzppcz\tuyiy3wp3n0uiaaygb8we.exe
- %WINDIR%\vlzppcz\axbqmfibyjg
- 'th####eceive.net':80
- 'cl####elieve.net':80
- 'th####uarter.net':80
- 'cl####eceive.net':80
- 'th###branch.net':80
- 'we####rquarter.net':80
- 'th####elieve.net':80
- 'cl###branch.net':80
- 'th###system.net':80
- 'pr####tneither.net':80
- 'th###trust.net':80
- 'pr####tsystem.net':80
- 'th###honor.net':80
- 'cl####uarter.net':80
- 'th####either.net':80
- 'pr####thonor.net':80
- 'am####quarter.net':80
- 'hi####ybelieve.net':80
- 'st####ebelieve.net':80
- 'hi####yreceive.net':80
- 'st####ereceive.net':80
- 'mo####gquarter.net':80
- 'ra####quarter.net':80
- 'hi####ybranch.net':80
- 'st####ebranch.net':80
- 'we####rbelieve.net':80
- 'am####believe.net':80
- 'we####rreceive.net':80
- 'am####receive.net':80
- 'hi####yquarter.net':80
- 'st####equarter.net':80
- 'we####rbranch.net':80
- 'am####branch.net':80
- http://th####eceive.net/index.php?me########
- http://cl####elieve.net/index.php?me########
- http://th####uarter.net/index.php?me########
- http://cl####eceive.net/index.php?me########
- http://th###branch.net/index.php?me########
- http://we####rquarter.net/index.php?me########
- http://th####elieve.net/index.php?me########
- http://cl###branch.net/index.php?me########
- http://th###system.net/index.php?me########
- http://pr####tneither.net/index.php?me########
- http://th###trust.net/index.php?me########
- http://pr####tsystem.net/index.php?me########
- http://th###honor.net/index.php?me########
- http://cl####uarter.net/index.php?me########
- http://th####either.net/index.php?me########
- http://pr####thonor.net/index.php?me########
- http://am####quarter.net/index.php?me########
- http://hi####ybelieve.net/index.php?me########
- http://st####ebelieve.net/index.php?me########
- http://hi####yreceive.net/index.php?me########
- http://st####ereceive.net/index.php?me########
- http://mo####gquarter.net/index.php?me########
- http://ra####quarter.net/index.php?me########
- http://hi####ybranch.net/index.php?me########
- http://st####ebranch.net/index.php?me########
- http://we####rbelieve.net/index.php?me########
- http://am####believe.net/index.php?me########
- http://we####rreceive.net/index.php?me########
- http://am####receive.net/index.php?me########
- http://hi####yquarter.net/index.php?me########
- http://st####equarter.net/index.php?me########
- http://we####rbranch.net/index.php?me########
- http://am####branch.net/index.php?me########
- DNS ASK th####eceive.net
- DNS ASK cl####elieve.net
- DNS ASK th####uarter.net
- DNS ASK cl####eceive.net
- DNS ASK th###branch.net
- DNS ASK we####rquarter.net
- DNS ASK th####elieve.net
- DNS ASK cl###branch.net
- DNS ASK cl####uarter.net
- DNS ASK pr####tsystem.net
- DNS ASK th###system.net
- DNS ASK pr####ttrust.net
- DNS ASK th###trust.net
- DNS ASK pr####thonor.net
- DNS ASK th###honor.net
- DNS ASK pr####tneither.net
- DNS ASK th####either.net
- DNS ASK hi####ybelieve.net
- DNS ASK st####ebelieve.net
- DNS ASK hi####yreceive.net
- DNS ASK st####ereceive.net
- DNS ASK mo####gquarter.net
- DNS ASK ra####quarter.net
- DNS ASK hi####ybranch.net
- DNS ASK st####ebranch.net
- DNS ASK st####equarter.net
- DNS ASK am####receive.net
- DNS ASK we####rbelieve.net
- DNS ASK am####quarter.net
- DNS ASK we####rreceive.net
- DNS ASK am####branch.net
- DNS ASK hi####yquarter.net
- DNS ASK am####believe.net
- DNS ASK we####rbranch.net
- ClassName: 'Shell_TrayWnd' WindowName: ''