Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Manager Location Bus Block Search' = '<SYSTEM32>\gqfxmhaddl.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\System Credential Copy File] 'ImagePath' = '<SYSTEM32>\gqfxmhaddl.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\System Credential Copy File] 'Start' = '00000002'
- '<SYSTEM32>\kivcpgij.exe' "<SYSTEM32>\gqfxmhaddl.exe"
- '<SYSTEM32>\gqfxmhaddl.exe'
- '%TEMP%\qyctetc9f66tujrlvpd0wt.exe'
- <SYSTEM32>\kivcpgij.exe
- <SYSTEM32>\omnvwtz\rng
- <SYSTEM32>\omnvwtz\cli
- <SYSTEM32>\omnvwtz\tst
- %TEMP%\qyctetc9f66tujrlvpd0wt.exe
- <SYSTEM32>\gqfxmhaddl.exe
- <SYSTEM32>\kivcpgij.exe
- <SYSTEM32>\gqfxmhaddl.exe
- %TEMP%\qyctetc9f66tujrlvpd0wt.exe
- '41.#6.21.75':48405
- '10#.#02.79.27':36272
- '15#.#82.245.137':33982
- '10#.#4.136.243':42581
- '10#.#46.77.146':33927
- '82.##7.164.91':40801
- '62.##.253.114':51156
- '2.##.167.151':22437
- '20#.#36.131.186':52293
- '18#.#42.183.115':26662
- '79.##.186.229':49038
- '18#.#55.235.72':28122
- '22#.#1.110.45':48008
- '72.##1.207.62':22399
- '19#.#7.134.20':44965
- '24.##9.216.168':33794
- '73.##.228.84':36884
- '12#.#60.123.173':36805
- '77.##7.13.68':30018
- '77.##8.205.139':22969
- '18#.#45.182.189':37331
- '98.##.239.20':20922
- '95.##.58.101':23245
- '86.##.69.232':41590
- '20#.#23.152.97':27682
- '21#.#07.110.82':26314
- '91.##.35.122':26126
- '93.##7.67.155':25640
- '18#.#21.233.245':46084
- '18#.#0.223.209':25741
- '18#.#49.85.10':32097
- '79.##7.196.121':45688
- '19#.#17.67.199':45860
- '81.##7.50.99':52074
- '18#.2.4.92':44843
- '17#.#50.138.208':20422
- '20#.#7.225.58':33073
- '78.##5.171.93':23699
- '10#.#84.231.210':47507
- '84.##8.128.25':27132
- '10#.#24.230.242':49777
- '87.##.238.184':44724
- '71.##6.195.178':41500
- '5.##.147.5':26337
- '18#.#39.175.243':37599
- '11#.#18.187.28':42065
- '86.##5.10.227':45279
- '19#.#6.240.249':21875
- '74.#5.64.25':22739
- '17#.37.2.43':44303
- '62.##1.108.194':20068
- '41.##8.41.238':29356
- '12#.#60.112.138':27440
- '12#.#89.4.21':49919
- '61.##6.2.217':25840
- '86.##5.19.130':27743
- '88.#48.36.4':25752
- '78.#7.87.58':21017
- '79.##3.139.198':21201
- '21#.#65.0.136':35711
- '94.##1.114.138':44254
- '81.##4.87.112':37714
- '19#.#47.86.10':25432
- '2.##.19.50':35833
- '80.##1.86.158':33631
- '18#.#50.164.217':37727
- '21#.#7.168.28':52231
- '5.##.19.242':27426
- '19#.#0.96.220':41884