Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Driver Offline Upgrade Remote Cryptographic' = '<SYSTEM32>\yfzryqgfbl.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Fax BitLocker TP Tracking Builder] 'ImagePath' = '<SYSTEM32>\yfzryqgfbl.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Fax BitLocker TP Tracking Builder] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\qhrcxocc.exe' "<SYSTEM32>\yfzryqgfbl.exe"
- '%WINDIR%\Temp\a8ptjxu2zjyjm.exe' -r 27336 tcp
- '%TEMP%\a8ptjxu2owajmbkjevbrd.exe'
- '<SYSTEM32>\yfzryqgfbl.exe'
- <SYSTEM32>\uhhesszfahmrod\run
- <SYSTEM32>\uhhesszfahmrod\rng
- %WINDIR%\Temp\a8ptjxu2zjyjm.exe
- <SYSTEM32>\uhhesszfahmrod\cfg
- <SYSTEM32>\qhrcxocc.exe
- %TEMP%\a8ptjxu2owajmbkjevbrd.exe
- <SYSTEM32>\uhhesszfahmrod\tst
- <SYSTEM32>\yfzryqgfbl.exe
- <SYSTEM32>\uhhesszfahmrod\etc
- <SYSTEM32>\qhrcxocc.exe
- <SYSTEM32>\yfzryqgfbl.exe
- %WINDIR%\Temp\a8ptjxu2zjyjm.exe
- <DRIVERS>\etc\hosts
- %TEMP%\a8ptjxu2owajmbkjevbrd.exe
- 'si###uter.net':80
- 'cl###shoe.net':80
- 'me###uter.net':80
- 'me###oon.net':80
- 'si###oon.net':80
- 'cl###moon.net':80
- 'da###oon.net':80
- 'da###ctober.net':80
- 'da###hoe.net':80
- 'cl####ctober.net':80
- 'si###ctober.net':80
- 'su###ymoon.net':80
- 'mo###oon.net':80
- 'mo###ctober.net':80
- 'mo###hoe.net':80
- 'su####october.net':80
- 'si###hoe.net':80
- 'me###ctober.net':80
- 'me###hoe.net':80
- 'su###youter.net':80
- 'mo###uter.net':80
- 'wi###ule.net':80
- 'du###ule.net':80
- 'du###unt.net':80
- 'du###how.net':80
- 'wi###unt.net':80
- 'si###show.net':80
- 'th###hunt.net':80
- 'th###show.net':80
- 'wi###ear.net':80
- 'du###ear.net':80
- 'wi###how.net':80
- 'tr###show.net':80
- 'mi###unt.net':80
- 'mi###how.net':80
- 'cl###outer.net':80
- 'da###uter.net':80
- 'mi###ear.net':80
- 'tr###hear.net':80
- 'tr###rule.net':80
- 'tr###hunt.net':80
- 'mi###ule.net':80
- 'su###yshoe.net':80
- 'wi###oon.net':80
- 'du###oon.net':80
- 'du###ctober.net':80
- 'du###hoe.net':80
- 'wi###ctober.net':80
- 'si###shoe.net':80
- 'th####ctober.net':80
- 'th###shoe.net':80
- 'wi###uter.net':80
- 'du###uter.net':80
- 'be##lxc.com':80
- 'mi###hown.net':80
- 'ab###ell.net':80
- 'mo###ugust.net':80
- 'cr#####onaraminta.net':80
- 'le###form.net':80
- 'al###being.net':80
- 'ri###nstorm.net':80
- 'ca####nbring.net':80
- 'mo###olor.net':80
- 'pr####tbottom.net':80
- 'th###hoe.net':80
- 'qu####ctober.net':80
- 'qu###shoe.net':80
- 'ca###uter.net':80
- 'he###uter.net':80
- 'qu###outer.net':80
- 'th###uter.net':80
- 'th###oon.net':80
- 'th###ctober.net':80
- 'qu###moon.net':80
- 'he###oon.net':80
- 'th###outer.net':80
- 'si###outer.net':80
- 'si###moon.net':80
- 'si####ctober.net':80
- 'th###moon.net':80
- 'he###ctober.net':80
- 'ca###oon.net':80
- 'ca###ctober.net':80
- 'ca###hoe.net':80
- 'he###hoe.net':80
- http://si###uter.net/index.php
- http://cl###shoe.net/index.php
- http://me###uter.net/index.php
- http://me###oon.net/index.php
- http://si###oon.net/index.php
- http://cl###moon.net/index.php
- http://da###oon.net/index.php
- http://da###ctober.net/index.php
- http://da###hoe.net/index.php
- http://cl####ctober.net/index.php
- http://si###ctober.net/index.php
- http://su###ymoon.net/index.php
- http://mo###oon.net/index.php
- http://mo###ctober.net/index.php
- http://mo###hoe.net/index.php
- http://su####october.net/index.php
- http://si###hoe.net/index.php
- http://me###ctober.net/index.php
- http://me###hoe.net/index.php
- http://su###youter.net/index.php
- http://mo###uter.net/index.php
- http://wi###ule.net/index.php
- http://du###ule.net/index.php
- http://du###unt.net/index.php
- http://du###how.net/index.php
- http://wi###unt.net/index.php
- http://si###show.net/index.php
- http://th###hunt.net/index.php
- http://th###show.net/index.php
- http://wi###ear.net/index.php
- http://du###ear.net/index.php
- http://wi###how.net/index.php
- http://tr###show.net/index.php
- http://mi###unt.net/index.php
- http://mi###how.net/index.php
- http://cl###outer.net/index.php
- http://da###uter.net/index.php
- http://mi###ear.net/index.php
- http://tr###hear.net/index.php
- http://tr###rule.net/index.php
- http://tr###hunt.net/index.php
- http://mi###ule.net/index.php
- http://su###yshoe.net/index.php
- http://wi###oon.net/index.php
- http://du###oon.net/index.php
- http://du###ctober.net/index.php
- http://du###hoe.net/index.php
- http://wi###ctober.net/index.php
- http://si###shoe.net/index.php
- http://th####ctober.net/index.php
- http://th###shoe.net/index.php
- http://wi###uter.net/index.php
- http://du###uter.net/index.php
- http://be##lxc.com/index.php
- http://mi###hown.net/index.php
- http://ab###ell.net/index.php
- http://mo###ugust.net/index.php
- http://cr#####onaraminta.net/index.php
- http://le###form.net/index.php
- http://al###being.net/index.php
- http://ri###nstorm.net/index.php
- http://ca####nbring.net/index.php
- http://mo###olor.net/index.php
- http://pr####tbottom.net/index.php
- http://th###hoe.net/index.php
- http://qu####ctober.net/index.php
- http://qu###shoe.net/index.php
- http://ca###uter.net/index.php
- http://he###uter.net/index.php
- http://qu###outer.net/index.php
- http://th###uter.net/index.php
- http://th###oon.net/index.php
- http://th###ctober.net/index.php
- http://qu###moon.net/index.php
- http://he###oon.net/index.php
- http://th###outer.net/index.php
- http://si###outer.net/index.php
- http://si###moon.net/index.php
- http://si####ctober.net/index.php
- http://th###moon.net/index.php
- http://he###ctober.net/index.php
- http://ca###oon.net/index.php
- http://ca###ctober.net/index.php
- http://ca###hoe.net/index.php
- http://he###hoe.net/index.php
- DNS ASK si###uter.net
- DNS ASK cl###shoe.net
- DNS ASK me###uter.net
- DNS ASK me###oon.net
- DNS ASK si###oon.net
- DNS ASK cl###moon.net
- DNS ASK da###oon.net
- DNS ASK da###ctober.net
- DNS ASK da###hoe.net
- DNS ASK cl####ctober.net
- DNS ASK si###ctober.net
- DNS ASK su###ymoon.net
- DNS ASK mo###oon.net
- DNS ASK mo###ctober.net
- DNS ASK mo###hoe.net
- DNS ASK su####october.net
- DNS ASK si###hoe.net
- DNS ASK me###ctober.net
- DNS ASK me###hoe.net
- DNS ASK su###youter.net
- DNS ASK mo###uter.net
- DNS ASK cl###outer.net
- DNS ASK du###ule.net
- DNS ASK wi###ear.net
- DNS ASK wi###ule.net
- DNS ASK wi###unt.net
- DNS ASK du###unt.net
- DNS ASK th###hunt.net
- DNS ASK si###hunt.net
- DNS ASK si###show.net
- DNS ASK du###ear.net
- DNS ASK th###show.net
- DNS ASK du###how.net
- DNS ASK mi###unt.net
- DNS ASK tr###hunt.net
- DNS ASK tr###show.net
- DNS ASK da###uter.net
- DNS ASK mi###how.net
- DNS ASK tr###hear.net
- DNS ASK wi###how.net
- DNS ASK mi###ear.net
- DNS ASK mi###ule.net
- DNS ASK tr###rule.net
- DNS ASK su###yshoe.net
- DNS ASK wi###oon.net
- DNS ASK du###oon.net
- DNS ASK du###ctober.net
- DNS ASK du###hoe.net
- DNS ASK wi###ctober.net
- DNS ASK si###shoe.net
- DNS ASK th####ctober.net
- DNS ASK th###shoe.net
- DNS ASK wi###uter.net
- DNS ASK du###uter.net
- DNS ASK be##lxc.com
- DNS ASK mi###hown.net
- DNS ASK ab###ell.net
- DNS ASK mo###ugust.net
- DNS ASK cr#####onaraminta.net
- DNS ASK le###form.net
- DNS ASK al###being.net
- DNS ASK ri###nstorm.net
- DNS ASK ca####nbring.net
- DNS ASK mo###olor.net
- DNS ASK pr####tbottom.net
- DNS ASK th###hoe.net
- DNS ASK qu####ctober.net
- DNS ASK qu###shoe.net
- DNS ASK ca###uter.net
- DNS ASK he###uter.net
- DNS ASK qu###outer.net
- DNS ASK th###uter.net
- DNS ASK th###oon.net
- DNS ASK th###ctober.net
- DNS ASK qu###moon.net
- DNS ASK he###oon.net
- DNS ASK th###outer.net
- DNS ASK si###outer.net
- DNS ASK si###moon.net
- DNS ASK si####ctober.net
- DNS ASK th###moon.net
- DNS ASK he###ctober.net
- DNS ASK ca###oon.net
- DNS ASK ca###ctober.net
- DNS ASK ca###hoe.net
- DNS ASK he###hoe.net
- '23#.#55.255.250':1900