Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AudioCard' = '%APPDATA%\AudioCard\AudioCard.exe'
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4200
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4480
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=3920
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=3932
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=3268
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=3768
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=2924
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5180
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7092
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6828
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7788
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6012
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5200
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4060
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6976
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5328
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7548
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7828
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7508
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7436
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7448
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7128
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7576
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7836
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6156
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4628
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5932
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6176
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7908
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5648
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=416
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=8028
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4228
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6776
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=3748
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=296
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5952
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6152
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=1152
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7068
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=8188
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4020
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6332
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=1176
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7288
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6508
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=8052
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7952
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4128
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=3220
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6276
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6476
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6356
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7716
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=8048
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=3648
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7268
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7272
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7112
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6992
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4400
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6408
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5100
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7308
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7072
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7312
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7512
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6988
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6592
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6848
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6912
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7352
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7972
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7992
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5148
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7808
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7528
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7692
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7792
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6752
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=2584
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=3072
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5832
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6556
- '%APPDATA%\AudioCard\MouseSoft.exe' -a sha256 -g no -o http://ge#####.#ining.eligius.st:8337 -u 1Bck3WpMJaA5rirP4G41o7LwjWPVySdXLR -p x -t 2
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4428
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6132
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6272
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4928
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4728
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6772
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5028
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6512
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5428
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6232
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6496
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4880
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5000
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6112
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4100
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=1436
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=1512
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=1244
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5904
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7036
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6968
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=7048
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6388
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6428
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6188
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6668
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=3548
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6252
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6472
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6452
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5732
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6052
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=188
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6292
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=4828
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=1180
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6212
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=940
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=3468
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=5228
- '%APPDATA%\AudioCard\MouseSoft.exe' /pid=6596
- '<SYSTEM32>\cmd.exe' (downloaded from the Internet)
- '%APPDATA%\AudioCard\MouseSoft.exe' (downloaded from the Internet)
- '<SYSTEM32>\attrib.exe' -s -h %APPDATA%\AudioCard
- <SYSTEM32>\cmd.exe
- %APPDATA%\AudioCard\phatk.cl
- %APPDATA%\AudioCard\miner.dll
- %APPDATA%\AudioCard\usft_ext.dll
- %APPDATA%\AudioCard\phatk.ptx
- %APPDATA%\AudioCard\coinutil.dll
- %APPDATA%\AudioCard\bdb.dll
- %APPDATA%\AudioCard\MouseSoft.exe
- %APPDATA%\AudioCard\btc-evergreen.il
- %APPDATA%\AudioCard\btc.il
- from <Full path to virus> to %APPDATA%\AudioCard\AudioCard.exe
- '19#.#3.167.160':80
- 'wp#d':80
- 19#.#3.167.160/sov1001/miner.dll
- 19#.#3.167.160/sov1001/coinutil.dll
- 19#.#3.167.160/sov1001/phatk.cl
- 19#.#3.167.160/sov1001/usft_ext.dll
- 19#.#3.167.160/sov1001/phatk.ptx
- 19#.#3.167.160/sov1001/coin-miner.exe
- wp#d/wpad.dat
- 19#.#3.167.160/sov1001/bdb.dll
- 19#.#3.167.160/sov1001/btc-evergreen.il
- 19#.#3.167.160/sov1001/btc.il
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'