Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'FFCJsvR5gnUk1EPoCVbfFCeS' = '"%APPDATA%\Mozilla\Extensions\dfrgfat.exe"'
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\cscript.exe
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\ctfmon.exe
- safari.exe
- opera.exe
- chrome.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1406' = '00000003'
- %APPDATA%\Mozilla\Extensions\dfrgfat.exe
- 'mr###gn3.jeo.cc':443
- '0y######xedfbfwxh.jeo.cc':443
- 'pm#####3qtnw04d.gmz.cc':443
- 'tv######lrcc63xos.umc.su':443
- 'cs####dkcz.jeo.cc':443
- 'br#####ujkdf7zd.umc.su':443
- 'e0#####fmly6gpp.gmz.cc':443
- 'f7###4v.gmz.cc':443
- '0v######sqlvi6d5uu.jeo.cc':443
- 'er###f.gmz.cc':443
- 'so####y317sq.umc.su':443
- 'jh######wn9vni9yzm.umc.su':443
- 'go#####xjoc1t.gmz.cc':443
- 's6#####4gfmq7.jeo.cc':443
- 'td###mn.umc.su':443
- '68#####lwdwgh7i8.umc.su':443
- 'go###o.umc.su':443
- 'co######rmifxr9ur.umc.su':443
- '7d####1tur.umc.su':443
- 'w9#####mhpipbtb.jeo.cc':443
- 'wp#####5einsm.gmz.cc':443
- 'yz#####7rrngn8w.jeo.cc':443
- 'qo####bp7i3z.gmz.cc':443
- 'hg####s9j.umc.su':443
- 'br#####eigwjrsl.umc.su':443
- 'y8###jp9.jeo.cc':443
- 'zj#####9qhka7711.jeo.cc':443
- 'p9####xki3y.jeo.cc':443
- DNS ASK tv######lrcc63xos.umc.su
- DNS ASK e0#####fmly6gpp.gmz.cc
- DNS ASK 0y######xedfbfwxh.jeo.cc
- DNS ASK mr###gn3.jeo.cc
- DNS ASK hg####s9j.umc.su
- DNS ASK qo####bp7i3z.gmz.cc
- DNS ASK br#####ujkdf7zd.umc.su
- DNS ASK cs####dkcz.jeo.cc
- DNS ASK f7###4v.gmz.cc
- DNS ASK so####y317sq.umc.su
- DNS ASK er###f.gmz.cc
- DNS ASK 0v######sqlvi6d5uu.jeo.cc
- DNS ASK jh######wn9vni9yzm.umc.su
- DNS ASK pm#####3qtnw04d.gmz.cc
- DNS ASK s6#####4gfmq7.jeo.cc
- DNS ASK go#####xjoc1t.gmz.cc
- DNS ASK yz#####7rrngn8w.jeo.cc
- DNS ASK 68#####lwdwgh7i8.umc.su
- DNS ASK td###mn.umc.su
- DNS ASK y8###jp9.jeo.cc
- DNS ASK go###o.umc.su
- DNS ASK w9#####mhpipbtb.jeo.cc
- DNS ASK 7d####1tur.umc.su
- DNS ASK co######rmifxr9ur.umc.su
- DNS ASK wp#####5einsm.gmz.cc
- DNS ASK nk######enubnhh1k.gmz.cc
- DNS ASK e6#####58hb0bc.gmz.cc
- DNS ASK br#####eigwjrsl.umc.su
- DNS ASK 4t######ix2l2dbwrg.gmz.cc
- DNS ASK p9####xki3y.jeo.cc
- DNS ASK zj#####9qhka7711.jeo.cc
- DNS ASK u5####bofmnq.gmz.cc
- DNS ASK yw###w.jeo.cc