Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IP WinHTTP Presentation List Collector' = '<SYSTEM32>\mfmivkbwlado.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Brightness Function Portable] 'ImagePath' = '<SYSTEM32>\mfmivkbwlado.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Brightness Function Portable] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\teiebbvq.exe' "<SYSTEM32>\mfmivkbwlado.exe"
- '%WINDIR%\Temp\ipdli0t2m0jxwil.exe' -r 32014 tcp
- '%TEMP%\ipdli0t2gboxwilk3q3of.exe'
- '<SYSTEM32>\mfmivkbwlado.exe'
- <SYSTEM32>\sponnyms\run
- <SYSTEM32>\sponnyms\rng
- %WINDIR%\Temp\ipdli0t2m0jxwil.exe
- <SYSTEM32>\sponnyms\cfg
- <SYSTEM32>\teiebbvq.exe
- %TEMP%\ipdli0t2gboxwilk3q3of.exe
- <SYSTEM32>\sponnyms\tst
- <SYSTEM32>\mfmivkbwlado.exe
- <SYSTEM32>\sponnyms\etc
- <SYSTEM32>\teiebbvq.exe
- <SYSTEM32>\mfmivkbwlado.exe
- %WINDIR%\Temp\ipdli0t2m0jxwil.exe
- <DRIVERS>\etc\hosts
- %TEMP%\ipdli0t2gboxwilk3q3of.exe
- 'ar###sound.net':80
- 'so###sound.net':80
- 'ar###green.net':80
- 'so###green.net':80
- 'up###ift.net':80
- 'wh###lift.net':80
- 'ar###hand.net':80
- 'so###hand.net':80
- 'so###lift.net':80
- 'th###ail.net':80
- 'dr###wore.net':80
- 'th###oad.net':80
- 'dr###mail.net':80
- 'th###here.net':80
- 'ar###lift.net':80
- 'th###ore.net':80
- 'dr###where.net':80
- 'up###reen.net':80
- 'sp###and.net':80
- 'sa###and.net':80
- 'sp###ound.net':80
- 'sa###ound.net':80
- 'gl###reen.net':80
- 'ta###green.net':80
- 'gl###ift.net':80
- 'ta###lift.net':80
- 'sa###reen.net':80
- 'wh###sound.net':80
- 'up###and.net':80
- 'wh###green.net':80
- 'up###ound.net':80
- 'sa###ift.net':80
- 'sp###reen.net':80
- 'wh###hand.net':80
- 'sp###ift.net':80
- 'gr###road.net':80
- 'eq###mail.net':80
- 'ta###where.net':80
- 'eq###road.net':80
- 'gr###wore.net':80
- 'eq###where.net':80
- 'gr###mail.net':80
- 'eq###wore.net':80
- 'gl###here.net':80
- 'th###while.net':80
- 'ef###tbuilt.net':80
- 'jo####ymeasure.net':80
- 'ri###nstorm.net':80
- 'gl###ore.net':80
- 'ta###wore.net':80
- 'gl###ail.net':80
- 'ta###mail.net':80
- 'gr###where.net':80
- 'fa###ail.net':80
- 'wa###wore.net':80
- 'fa###oad.net':80
- 'wa###mail.net':80
- 'fa###here.net':80
- 'dr###road.net':80
- 'fa###ore.net':80
- 'wa###where.net':80
- 'wa###road.net':80
- 'sp###mail.net':80
- 'vi###mail.net':80
- 'sp###road.net':80
- 'vi###road.net':80
- 'sp###where.net':80
- 'vi###where.net':80
- 'sp###wore.net':80
- 'vi###wore.net':80
- http://ar###sound.net/index.php
- http://so###sound.net/index.php
- http://ar###green.net/index.php
- http://so###green.net/index.php
- http://up###ift.net/index.php
- http://wh###lift.net/index.php
- http://ar###hand.net/index.php
- http://so###hand.net/index.php
- http://so###lift.net/index.php
- http://th###ail.net/index.php
- http://dr###wore.net/index.php
- http://th###oad.net/index.php
- http://dr###mail.net/index.php
- http://th###here.net/index.php
- http://ar###lift.net/index.php
- http://th###ore.net/index.php
- http://dr###where.net/index.php
- http://up###reen.net/index.php
- http://sp###and.net/index.php
- http://sa###and.net/index.php
- http://sp###ound.net/index.php
- http://sa###ound.net/index.php
- http://gl###reen.net/index.php
- http://ta###green.net/index.php
- http://gl###ift.net/index.php
- http://ta###lift.net/index.php
- http://sa###reen.net/index.php
- http://wh###sound.net/index.php
- http://up###and.net/index.php
- http://wh###green.net/index.php
- http://up###ound.net/index.php
- http://sa###ift.net/index.php
- http://sp###reen.net/index.php
- http://wh###hand.net/index.php
- http://sp###ift.net/index.php
- http://gr###road.net/index.php
- http://eq###mail.net/index.php
- http://ta###where.net/index.php
- http://eq###road.net/index.php
- http://gr###wore.net/index.php
- http://eq###where.net/index.php
- http://gr###mail.net/index.php
- http://eq###wore.net/index.php
- http://gl###here.net/index.php
- http://th###while.net/index.php
- http://ef###tbuilt.net/index.php
- http://jo####ymeasure.net/index.php
- http://ri###nstorm.net/index.php
- http://gl###ore.net/index.php
- http://ta###wore.net/index.php
- http://gl###ail.net/index.php
- http://ta###mail.net/index.php
- http://gr###where.net/index.php
- http://fa###ail.net/index.php
- http://wa###wore.net/index.php
- http://fa###oad.net/index.php
- http://wa###mail.net/index.php
- http://fa###here.net/index.php
- http://dr###road.net/index.php
- http://fa###ore.net/index.php
- http://wa###where.net/index.php
- http://wa###road.net/index.php
- http://sp###mail.net/index.php
- http://vi###mail.net/index.php
- http://sp###road.net/index.php
- http://vi###road.net/index.php
- http://sp###where.net/index.php
- http://vi###where.net/index.php
- http://sp###wore.net/index.php
- http://vi###wore.net/index.php
- DNS ASK ar###sound.net
- DNS ASK so###sound.net
- DNS ASK ar###green.net
- DNS ASK so###green.net
- DNS ASK ar###hand.net
- DNS ASK wh###lift.net
- DNS ASK up###reen.net
- DNS ASK so###hand.net
- DNS ASK up###ift.net
- DNS ASK th###ail.net
- DNS ASK dr###wore.net
- DNS ASK th###oad.net
- DNS ASK dr###mail.net
- DNS ASK th###ore.net
- DNS ASK ar###lift.net
- DNS ASK so###lift.net
- DNS ASK dr###where.net
- DNS ASK th###here.net
- DNS ASK sp###and.net
- DNS ASK sa###and.net
- DNS ASK sp###ound.net
- DNS ASK sa###ound.net
- DNS ASK gl###ift.net
- DNS ASK ta###green.net
- DNS ASK gl###ound.net
- DNS ASK ta###lift.net
- DNS ASK gl###reen.net
- DNS ASK wh###sound.net
- DNS ASK up###and.net
- DNS ASK wh###green.net
- DNS ASK up###ound.net
- DNS ASK wh###hand.net
- DNS ASK sp###reen.net
- DNS ASK sa###reen.net
- DNS ASK sp###ift.net
- DNS ASK sa###ift.net
- DNS ASK gr###road.net
- DNS ASK eq###mail.net
- DNS ASK ta###where.net
- DNS ASK eq###road.net
- DNS ASK gr###wore.net
- DNS ASK eq###where.net
- DNS ASK gr###mail.net
- DNS ASK eq###wore.net
- DNS ASK gl###here.net
- DNS ASK th###while.net
- DNS ASK ef###tbuilt.net
- DNS ASK jo####ymeasure.net
- DNS ASK ri###nstorm.net
- DNS ASK gl###ore.net
- DNS ASK ta###wore.net
- DNS ASK gl###ail.net
- DNS ASK ta###mail.net
- DNS ASK gr###where.net
- DNS ASK fa###ail.net
- DNS ASK wa###wore.net
- DNS ASK fa###oad.net
- DNS ASK wa###mail.net
- DNS ASK fa###here.net
- DNS ASK dr###road.net
- DNS ASK fa###ore.net
- DNS ASK wa###where.net
- DNS ASK wa###road.net
- DNS ASK sp###mail.net
- DNS ASK vi###mail.net
- DNS ASK sp###road.net
- DNS ASK vi###road.net
- DNS ASK sp###where.net
- DNS ASK vi###where.net
- DNS ASK sp###wore.net
- DNS ASK vi###wore.net
- '23#.#55.255.250':1900