Technical Information
- [HKCU\Software\Classes\ms-settings\shell\open\command] '' = 'cmd /c \"<Full path to file>\" && timeout 3 && reg delete \"HKCU\\Software\\Classes\\ms-settings\" /f'
- %TEMP%\passwords.txt
- %TEMP%\uac_done.txt
- %TEMP%\windowsupdate.log
- nul
- %TEMP%\passwords.txt
- 'ip##pi.com':80
- 'ra#.####ubusercontent.com':443
- '<LOCALNET>.1.1':445
- '<LOCALNET>.0.2':445
- '<LOCALNET>.1.2':445
- '<LOCALNET_GATEWAY>':445
- '<LOCALNET_GATEWAY>':135
- '<LOCALNET>.1.1':135
- '<LOCALNET>.0.2':135
- '<LOCALNET>.1.2':135
- '<LOCALNET>.0.2':139
- '<LOCALNET_GATEWAY>':139
- '<LOCALNET>.1.1':139
- '<LOCALNET>.1.2':139
- '<LOCALNET>.0.2':22
- '<LOCALNET>.1.1':22
- '<LOCALNET>.1.2':22
- '<LOCALNET_GATEWAY>':22
- '<LOCALNET>.0.2':3389
- '<LOCALNET_GATEWAY>':3389
- '<LOCALNET>.1.2':3389
- '<LOCALNET>.1.1':3389
- '<LOCALNET>.0.3':445
- '<LOCALNET>..0.3':445
- '<LOCALNET>.1.3':445
- '<LOCALNET>..0.2':445
- '<LOCALNET>.1.4':445
- '<LOCALNET>.1.3':135
- '<LOCALNET>..0.3':135
- '<LOCALNET>.0.3':135
- '<LOCALNET>..0.2':135
- '<LOCALNET>.1.4':135
- '<LOCALNET>..0.3':139
- '<LOCALNET>.1.3':139
- '<LOCALNET>.0.3':139
- '<LOCALNET>..0.2':139
- '<LOCALNET>.1.4':139
- '<LOCALNET>.0.3':22
- '<LOCALNET>..0.2':22
- '<LOCALNET>.1.3':22
- '<LOCALNET>..0.3':22
- '<LOCALNET>.1.4':22
- '<LOCALNET>.1.3':3389
- '<LOCALNET>..0.3':3389
- '<LOCALNET>..0.2':3389
- '<LOCALNET>.0.3':3389
- '<LOCALNET>.1.4':3389
- '<LOCALNET>.0.5':445
- '<LOCALNET>.1.5':445
- '<LOCALNET>..0.5':445
- '<LOCALNET>.0.4':445
- '<LOCALNET>..0.4':445
- '<LOCALNET>.0.5':135
- '<LOCALNET>.1.5':135
- '<LOCALNET>..0.5':135
- '<LOCALNET>..0.4':135
- '<LOCALNET>.0.4':135
- '<LOCALNET>.0.5':139
- '<LOCALNET>.1.5':139
- '<LOCALNET>..0.5':139
- '<LOCALNET>.0.4':139
- '<LOCALNET>..0.4':139
- '<LOCALNET>.0.5':22
- '<LOCALNET>..0.5':22
- '<LOCALNET>.1.5':22
- '<LOCALNET>.0.4':22
- '<LOCALNET>..0.4':22
- '<LOCALNET>.0.5':3389
- '<LOCALNET>..0.5':3389
- '<LOCALNET>.1.5':3389
- '<LOCALNET>..0.4':3389
- '<LOCALNET>.0.4':3389
- '<LOCALNET>.0.7':445
- '<LOCALNET>.0.6':445
- '<LOCALNET>.1.7':445
- '<LOCALNET>..0.6':445
- '<LOCALNET>.1.6':445
- '<LOCALNET>.0.7':135
- '<LOCALNET>.1.7':135
- '<LOCALNET>.0.6':135
- '<LOCALNET>..0.6':135
- '<LOCALNET>.1.6':135
- '<LOCALNET>.1.7':139
- '<LOCALNET>.0.6':139
- '<LOCALNET>.0.7':139
- '<LOCALNET>..0.6':139
- '<LOCALNET>.1.6':139
- '<LOCALNET>.0.7':22
- '<LOCALNET>.1.7':22
- '<LOCALNET>.0.6':22
- '<LOCALNET>..0.6':22
- '<LOCALNET>.1.6':22
- '<LOCALNET>.0.6':3389
- '<LOCALNET>.1.7':3389
- '<LOCALNET>.0.7':3389
- '<LOCALNET>..0.6':3389
- '<LOCALNET>.1.6':3389
- '<LOCALNET>.1.8':445
- '<LOCALNET>.1.9':445
- '<LOCALNET>..0.7':445
- '<LOCALNET>.0.8':445
- '<LOCALNET>..0.8':445
- '<LOCALNET>.1.9':135
- '<LOCALNET>.1.8':135
- '<LOCALNET>.0.8':135
- '<LOCALNET>..0.7':135
- '<LOCALNET>..0.8':135
- '<LOCALNET>.1.8':139
- '<LOCALNET>.1.9':139
- '<LOCALNET>..0.7':139
- '<LOCALNET>.0.8':139
- '<LOCALNET>..0.8':139
- '<LOCALNET>.1.9':22
- '<LOCALNET>.1.8':22
- '<LOCALNET>.0.8':22
- '<LOCALNET>..0.8':22
- '<LOCALNET>..0.7':22
- '<LOCALNET>.1.8':3389
- '<LOCALNET>.1.9':3389
- '<LOCALNET>..0.7':3389
- '<LOCALNET>.0.8':3389
- '<LOCALNET>..0.8':3389
- '<LOCALNET>..0.10':445
- '<LOCALNET>..0.9':445
- '<LOCALNET>.1.10':445
- '<LOCALNET>.0.10':445
- '<LOCALNET>.0.9':445
- '<LOCALNET>..0.9':135
- '<LOCALNET>..0.10':135
- '<LOCALNET>.1.10':135
- '<LOCALNET>.0.9':135
- '<LOCALNET>.0.10':135
- '<LOCALNET>..0.9':139
- '<LOCALNET>..0.10':139
- '<LOCALNET>.1.10':139
- '<LOCALNET>.0.10':139
- '<LOCALNET>.0.9':139
- '<LOCALNET>..0.9':22
- '<LOCALNET>..0.10':22
- '<LOCALNET>.1.10':22
- '<LOCALNET>.0.9':22
- '<LOCALNET>.0.10':22
- '<LOCALNET>..0.9':3389
- '<LOCALNET>..0.10':3389
- '<LOCALNET>.1.10':3389
- '<LOCALNET>.0.10':3389
- '<LOCALNET>.0.9':3389
- '<LOCALNET>.0.11':445
- '<LOCALNET>.1.11':445
- '<LOCALNET>.1.12':445
- '<LOCALNET>.0.12':445
- '<LOCALNET>..0.11':445
- '<LOCALNET>.1.11':135
- '<LOCALNET>.0.11':135
- '<LOCALNET>.1.12':135
- '<LOCALNET>.0.12':135
- '<LOCALNET>..0.11':135
- '<LOCALNET>.1.11':139
- '<LOCALNET>.0.11':139
- '<LOCALNET>.1.12':139
- '<LOCALNET>..0.11':139
- '<LOCALNET>.0.12':139
- '<LOCALNET>.0.11':22
- '<LOCALNET>.0.12':22
- '<LOCALNET>..0.11':22
- '<LOCALNET>.1.11':22
- '<LOCALNET>.1.12':22
- '<LOCALNET>.1.11':3389
- '<LOCALNET>.1.12':3389
- '<LOCALNET>..0.11':3389
- '<LOCALNET>.0.12':3389
- '<LOCALNET>.0.11':3389
- '<LOCALNET>..0.13':445
- '<LOCALNET>.1.14':445
- '<LOCALNET>.1.13':445
- '<LOCALNET>.0.13':445
- '<LOCALNET>..0.12':445
- '<LOCALNET>..0.13':135
- '<LOCALNET>.1.14':135
- '<LOCALNET>.1.13':135
- '<LOCALNET>.0.13':135
- '<LOCALNET>..0.12':135
- '<LOCALNET>.1.13':139
- '<LOCALNET>..0.13':139
- '<LOCALNET>.1.14':139
- '<LOCALNET>.0.13':139
- '<LOCALNET>..0.12':139
- '<LOCALNET>.1.13':22
- '<LOCALNET>..0.13':22
- '<LOCALNET>.1.14':22
- '<LOCALNET>.0.13':22
- '<LOCALNET>..0.12':22
- '<LOCALNET>..0.13':3389
- '<LOCALNET>.1.13':3389
- '<LOCALNET>.1.14':3389
- '<LOCALNET>.0.13':3389
- '<LOCALNET>..0.12':3389
- http://ip##pi.com/line/?fi################
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?76##############
- 'ra#.####ubusercontent.com':443
- DNS ASK ip##pi.com
- DNS ASK ra#.####ubusercontent.com
- '<SYSTEM32>\fodhelper.exe'
- '<SYSTEM32>\cmd.exe' /c \"<Full path to file>\" && timeout 3 && reg delete \"HKCU\\Software\\Classes\\ms-settings\" /f
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.0.2 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.1 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.1.2 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.1.1 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.0.1 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.0.1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.1.1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.1.2
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.0.2
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.1.3 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.3 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.2 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.0.3 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.1.4 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.2
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.3
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.0.3
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.1.3
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.1.4
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.4 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.1.5 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.0.5 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.5 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.0.4 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.1.5
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.5
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.0.5
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.4
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.0.4
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.6 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.1.7 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.1.6 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.0.6 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.0.7 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.1.7
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.6
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.0.6
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.0.7
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.1.6
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.7 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.0.8 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.8 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.1.8 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.1.9 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.7
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.0.8
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.8
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.1.8
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.1.9
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.168.0.9 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.10 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.10 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.9 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.10 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.10
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.10
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.9
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.168.0.9
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.10
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.11 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.12 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.12 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.11 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.11 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.11
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.12
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.12
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.11
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.11
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.13 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.13 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.13 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.14 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.12 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.13
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.13
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.13
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.14
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.12
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.15 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.14 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.14 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.15 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.15 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.15
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.14
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.15
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.14
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.15
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.16 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.16 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.16 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.17 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.17 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.17
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.16
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.16
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.16
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.17
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.17 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.18 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.18 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.18 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.19 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.17
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.18
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.18
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.19
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.18
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.19 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.19 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.20 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.20 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.20 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.19
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.20
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.20
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.20
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.19
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 10.#.0.21 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.21 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.22 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.0.22 >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 1000 19#.#68.1.21 >nul 2>&1
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.21
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.21
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.1.22
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 10.#.0.21
- '<SYSTEM32>\ping.exe' -n 1 -w 1000 19#.#68.0.22
- '<SYSTEM32>\fodhelper.exe' ' (with hidden window)