Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Thread Acquisition Management' = '<SYSTEM32>\vahcltc.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Instrumentation Extender Logon] 'ImagePath' = '<SYSTEM32>\vahcltc.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Instrumentation Extender Logon] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\bfahiutyaykh.exe' "<SYSTEM32>\vahcltc.exe"
- '%WINDIR%\Temp\yuguzimi32saeblb.exe' -r 26329 tcp
- '%TEMP%\yuguzimi2pl0eblbhtoukwd1.exe'
- '<SYSTEM32>\vahcltc.exe'
- <SYSTEM32>\xicnzjgycezieg\run
- <SYSTEM32>\xicnzjgycezieg\rng
- %WINDIR%\Temp\yuguzimi32saeblb.exe
- <SYSTEM32>\xicnzjgycezieg\cfg
- <SYSTEM32>\bfahiutyaykh.exe
- %TEMP%\yuguzimi2pl0eblbhtoukwd1.exe
- <SYSTEM32>\xicnzjgycezieg\tst
- <SYSTEM32>\vahcltc.exe
- <SYSTEM32>\xicnzjgycezieg\etc
- <SYSTEM32>\bfahiutyaykh.exe
- <SYSTEM32>\vahcltc.exe
- %WINDIR%\Temp\yuguzimi32saeblb.exe
- <DRIVERS>\etc\hosts
- %TEMP%\yuguzimi2pl0eblbhtoukwd1.exe
- 'gr###best.net':80
- 'eq###best.net':80
- 'eq#####nsiderable.net':80
- 'eq###easy.net':80
- 'gr#####nsiderable.net':80
- 'gl###asy.net':80
- 'ta#####nsiderable.net':80
- 'ta###easy.net':80
- 'gr###them.net':80
- 'eq###them.net':80
- 'gr###easy.net':80
- 'sp###easy.net':80
- 'vi#####nsiderable.net':80
- 'vi###easy.net':80
- 'fa###hem.net':80
- 'wa###them.net':80
- 'vi###them.net':80
- 'sp###them.net':80
- 'sp###best.net':80
- 'sp#####nsiderable.net':80
- 'vi###best.net':80
- 'up###asy.net':80
- 'wh#####nsiderable.net':80
- 'wh###easy.net':80
- 'sa###hem.net':80
- 'sp###hem.net':80
- 'af###sllc.com':80
- 'ri###nstorm.net':80
- 'be##lxc.com':80
- 'up#####siderable.net':80
- 'de###lxc.com':80
- 'sp###est.net':80
- 'ta###them.net':80
- 'gl###hem.net':80
- 'gl###est.net':80
- 'gl#####siderable.net':80
- 'ta###best.net':80
- 'sp#####siderable.net':80
- 'sa###est.net':80
- 'sa#####siderable.net':80
- 'sa###asy.net':80
- 'sp###asy.net':80
- http://gr###best.net/index.php
- http://eq###best.net/index.php
- http://eq#####nsiderable.net/index.php
- http://eq###easy.net/index.php
- http://gr#####nsiderable.net/index.php
- http://gl###asy.net/index.php
- http://ta#####nsiderable.net/index.php
- http://ta###easy.net/index.php
- http://gr###them.net/index.php
- http://eq###them.net/index.php
- http://gr###easy.net/index.php
- http://sp###easy.net/index.php
- http://vi#####nsiderable.net/index.php
- http://vi###easy.net/index.php
- http://fa###hem.net/index.php
- http://wa###them.net/index.php
- http://vi###them.net/index.php
- http://sp###them.net/index.php
- http://sp###best.net/index.php
- http://sp#####nsiderable.net/index.php
- http://vi###best.net/index.php
- http://up###asy.net/index.php
- http://wh#####nsiderable.net/index.php
- http://wh###easy.net/index.php
- http://sa###hem.net/index.php
- http://sp###hem.net/index.php
- http://af###sllc.com/index.php
- http://ri###nstorm.net/index.php
- http://be##lxc.com/index.php
- http://up#####siderable.net/index.php
- http://de###lxc.com/index.php
- http://sp###est.net/index.php
- http://ta###them.net/index.php
- http://gl###hem.net/index.php
- http://gl###est.net/index.php
- http://gl#####siderable.net/index.php
- http://ta###best.net/index.php
- http://sp#####siderable.net/index.php
- http://sa###est.net/index.php
- http://sa#####siderable.net/index.php
- http://sa###asy.net/index.php
- http://sp###asy.net/index.php
- DNS ASK eq#####nsiderable.net
- DNS ASK gr###best.net
- DNS ASK gr#####nsiderable.net
- DNS ASK gr###easy.net
- DNS ASK eq###easy.net
- DNS ASK eq###best.net
- DNS ASK gl###asy.net
- DNS ASK ta#####nsiderable.net
- DNS ASK ta###easy.net
- DNS ASK gr###them.net
- DNS ASK eq###them.net
- DNS ASK vi###easy.net
- DNS ASK sp###easy.net
- DNS ASK wa###them.net
- DNS ASK wa###best.net
- DNS ASK fa###hem.net
- DNS ASK vi#####nsiderable.net
- DNS ASK vi###them.net
- DNS ASK sp###them.net
- DNS ASK sp###best.net
- DNS ASK sp#####nsiderable.net
- DNS ASK vi###best.net
- DNS ASK up###asy.net
- DNS ASK wh#####nsiderable.net
- DNS ASK wh###easy.net
- DNS ASK sa###hem.net
- DNS ASK sp###hem.net
- DNS ASK af###sllc.com
- DNS ASK ri###nstorm.net
- DNS ASK be##lxc.com
- DNS ASK up#####siderable.net
- DNS ASK de###lxc.com
- DNS ASK sp###est.net
- DNS ASK ta###them.net
- DNS ASK gl###hem.net
- DNS ASK gl###est.net
- DNS ASK gl#####siderable.net
- DNS ASK ta###best.net
- DNS ASK sp#####siderable.net
- DNS ASK sa###est.net
- DNS ASK sa#####siderable.net
- DNS ASK sa###asy.net
- DNS ASK sp###asy.net
- '23#.#55.255.250':1900