Technical Information
- [<HKLM>\System\CurrentControlSet\Services\dbgeng] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\dbgeng] 'ImagePath' = '"%WINDIR%\SysWOW64\api-ms-win-crt-utility-l1-1-0\dbgeng.exe"'
- 'dbgeng' "%WINDIR%\SysWOW64\api-ms-win-crt-utility-l1-1-0\dbgeng.exe"
- 'dbgeng' %WINDIR%\SysWOW64\api-ms-win-crt-utility-l1-1-0\dbgeng.exe
- from <Full path to file> to %WINDIR%\syswow64\api-ms-win-crt-utility-l1-1-0\dbgeng.exe
- '15#.#86.9.160':80
- '80.##9.176.206':80
- '94.##.62.116':8080
- '59.##8.253.194':8080
- http://59.###.253.194:8080/dozKHgciGvDq93WG4/j05bI4H0dwz/LwEY471/dNBvxWjwZ/cp2VINE3kBJWKwLh6N/CONetZIC0J38ZD/ via 59.##8.253.194