Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Tracking Redirector IP Superfetch Panel' = '<SYSTEM32>\cfqivbwrzzy.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Shadow Wired RPC Policy Coordinator] 'ImagePath' = '<SYSTEM32>\cfqivbwrzzy.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Shadow Wired RPC Policy Coordinator] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\fnffljcdpshe.exe' "<SYSTEM32>\cfqivbwrzzy.exe"
- '%WINDIR%\Temp\j7pyt6ff3l6qbpmb.exe' -r 29723 tcp
- '%TEMP%\j7pyt6fazmrcrpmboewgmd6.exe'
- '<SYSTEM32>\cfqivbwrzzy.exe'
- <SYSTEM32>\dxgnkgsym\run
- <SYSTEM32>\dxgnkgsym\rng
- %WINDIR%\Temp\j7pyt6ff3l6qbpmb.exe
- <SYSTEM32>\dxgnkgsym\cfg
- %TEMP%\j7pyt6fazmrcrpmboewgmd6.exe
- <SYSTEM32>\dxgnkgsym\tst
- <SYSTEM32>\fnffljcdpshe.exe
- <SYSTEM32>\cfqivbwrzzy.exe
- <SYSTEM32>\fnffljcdpshe.exe
- <SYSTEM32>\cfqivbwrzzy.exe
- %WINDIR%\Temp\j7pyt6ff3l6qbpmb.exe
- %TEMP%\j7pyt6fazmrcrpmboewgmd6.exe
- 'th###sound.net':80
- 'si###sound.net':80
- 'th###green.net':80
- 'si###green.net':80
- 'ca###ift.net':80
- 'he###ift.net':80
- 'th###hand.net':80
- 'si###hand.net':80
- 'si###lift.net':80
- 'du###reen.net':80
- 'wi###ound.net':80
- 'du###ift.net':80
- 'wi###reen.net':80
- 'du###and.net':80
- 'th###lift.net':80
- 'du###ound.net':80
- 'wi###and.net':80
- 'ca###reen.net':80
- 'qu###hand.net':80
- 'th###and.net':80
- 'qu###sound.net':80
- 'th###ound.net':80
- 'su###ygreen.net':80
- 'mo###reen.net':80
- 'su###ylift.net':80
- 'mo###ift.net':80
- 'th###reen.net':80
- 'he###ound.net':80
- 'ca###and.net':80
- 'he###reen.net':80
- 'ca###ound.net':80
- 'th###ift.net':80
- 'qu###green.net':80
- 'he###and.net':80
- 'qu###lift.net':80
- 'th###while.net':80
- 'me###ail.net':80
- 'ri###nstorm.net':80
- 'ef###tbuilt.net':80
- 'si###ore.net':80
- 'me###here.net':80
- 'si###ail.net':80
- 'me###ore.net':80
- 'of####urprise.net':80
- 'de####promise.net':80
- 'se####strong.net':80
- 'or###thrown.net':80
- 'jo####ymeasure.net':80
- 'ch####nother.net':80
- 'gw#####ynhuddleston.net':80
- 'si######edwerryhouse.net':80
- 'mo####gduring.net':80
- 'si###here.net':80
- 'tr###green.net':80
- 'mi###ound.net':80
- 'tr###lift.net':80
- 'mi###reen.net':80
- 'tr###hand.net':80
- 'wi###ift.net':80
- 'tr###sound.net':80
- 'mi###and.net':80
- 'mi###ift.net':80
- 'cl###mail.net':80
- 'da###ail.net':80
- 'cl###road.net':80
- 'da###oad.net':80
- 'cl###where.net':80
- 'da###here.net':80
- 'cl###wore.net':80
- 'da###ore.net':80
- http://th###sound.net/index.php
- http://si###sound.net/index.php
- http://th###green.net/index.php
- http://si###green.net/index.php
- http://ca###ift.net/index.php
- http://he###ift.net/index.php
- http://th###hand.net/index.php
- http://si###hand.net/index.php
- http://si###lift.net/index.php
- http://du###reen.net/index.php
- http://wi###ound.net/index.php
- http://du###ift.net/index.php
- http://wi###reen.net/index.php
- http://du###and.net/index.php
- http://th###lift.net/index.php
- http://du###ound.net/index.php
- http://wi###and.net/index.php
- http://ca###reen.net/index.php
- http://qu###hand.net/index.php
- http://th###and.net/index.php
- http://qu###sound.net/index.php
- http://th###ound.net/index.php
- http://su###ygreen.net/index.php
- http://mo###reen.net/index.php
- http://su###ylift.net/index.php
- http://mo###ift.net/index.php
- http://th###reen.net/index.php
- http://he###ound.net/index.php
- http://ca###and.net/index.php
- http://he###reen.net/index.php
- http://ca###ound.net/index.php
- http://th###ift.net/index.php
- http://qu###green.net/index.php
- http://he###and.net/index.php
- http://qu###lift.net/index.php
- http://th###while.net/index.php
- http://me###ail.net/index.php
- http://ri###nstorm.net/index.php
- http://ef###tbuilt.net/index.php
- http://si###ore.net/index.php
- http://me###here.net/index.php
- http://si###ail.net/index.php
- http://me###ore.net/index.php
- http://of####urprise.net/index.php
- http://de####promise.net/index.php
- http://se####strong.net/index.php
- http://or###thrown.net/index.php
- http://jo####ymeasure.net/index.php
- http://ch####nother.net/index.php
- http://gw#####ynhuddleston.net/index.php
- http://si######edwerryhouse.net/index.php
- http://mo####gduring.net/index.php
- http://si###here.net/index.php
- http://tr###green.net/index.php
- http://mi###ound.net/index.php
- http://tr###lift.net/index.php
- http://mi###reen.net/index.php
- http://tr###hand.net/index.php
- http://wi###ift.net/index.php
- http://tr###sound.net/index.php
- http://mi###and.net/index.php
- http://mi###ift.net/index.php
- http://cl###mail.net/index.php
- http://da###ail.net/index.php
- http://cl###road.net/index.php
- http://da###oad.net/index.php
- http://cl###where.net/index.php
- http://da###here.net/index.php
- http://cl###wore.net/index.php
- http://da###ore.net/index.php
- DNS ASK th###sound.net
- DNS ASK si###sound.net
- DNS ASK th###green.net
- DNS ASK si###green.net
- DNS ASK th###hand.net
- DNS ASK he###ift.net
- DNS ASK ca###reen.net
- DNS ASK si###hand.net
- DNS ASK ca###ift.net
- DNS ASK du###reen.net
- DNS ASK wi###ound.net
- DNS ASK du###ift.net
- DNS ASK wi###reen.net
- DNS ASK du###ound.net
- DNS ASK th###lift.net
- DNS ASK si###lift.net
- DNS ASK wi###and.net
- DNS ASK du###and.net
- DNS ASK qu###hand.net
- DNS ASK th###and.net
- DNS ASK qu###sound.net
- DNS ASK th###ound.net
- DNS ASK su###ylift.net
- DNS ASK mo###reen.net
- DNS ASK su###ysound.net
- DNS ASK mo###ift.net
- DNS ASK su###ygreen.net
- DNS ASK he###ound.net
- DNS ASK ca###and.net
- DNS ASK he###reen.net
- DNS ASK ca###ound.net
- DNS ASK he###and.net
- DNS ASK qu###green.net
- DNS ASK th###reen.net
- DNS ASK qu###lift.net
- DNS ASK th###ift.net
- DNS ASK th###while.net
- DNS ASK me###ail.net
- DNS ASK ri###nstorm.net
- DNS ASK ef###tbuilt.net
- DNS ASK si###ore.net
- DNS ASK me###here.net
- DNS ASK si###ail.net
- DNS ASK me###ore.net
- DNS ASK of####urprise.net
- DNS ASK de####promise.net
- DNS ASK se####strong.net
- DNS ASK or###thrown.net
- DNS ASK jo####ymeasure.net
- DNS ASK ch####nother.net
- DNS ASK gw#####ynhuddleston.net
- DNS ASK si######edwerryhouse.net
- DNS ASK mo####gduring.net
- DNS ASK si###here.net
- DNS ASK tr###green.net
- DNS ASK mi###ound.net
- DNS ASK tr###lift.net
- DNS ASK mi###reen.net
- DNS ASK tr###hand.net
- DNS ASK wi###ift.net
- DNS ASK tr###sound.net
- DNS ASK mi###and.net
- DNS ASK mi###ift.net
- DNS ASK cl###mail.net
- DNS ASK da###ail.net
- DNS ASK cl###road.net
- DNS ASK da###oad.net
- DNS ASK cl###where.net
- DNS ASK da###here.net
- DNS ASK cl###wore.net
- DNS ASK da###ore.net
- '23#.#55.255.250':1900