Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'List IKE Tools ActiveX Disk' = '<SYSTEM32>\rqawsqps.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Host Collector Port File Office Files] 'ImagePath' = '<SYSTEM32>\rqawsqps.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Host Collector Port File Office Files] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\idofqbhjfat.exe' "<SYSTEM32>\rqawsqps.exe"
- '%WINDIR%\Temp\pclvivam3gucbmh.exe' -r 51212 tcp
- '%TEMP%\pclvivam3026bmhckp2nqdj.exe'
- '<SYSTEM32>\rqawsqps.exe'
- <SYSTEM32>\cyxavba\run
- <SYSTEM32>\cyxavba\rng
- %WINDIR%\Temp\pclvivam3gucbmh.exe
- <SYSTEM32>\cyxavba\cfg
- <SYSTEM32>\idofqbhjfat.exe
- %TEMP%\pclvivam3026bmhckp2nqdj.exe
- <SYSTEM32>\cyxavba\tst
- <SYSTEM32>\rqawsqps.exe
- <SYSTEM32>\cyxavba\etc
- <SYSTEM32>\idofqbhjfat.exe
- <SYSTEM32>\rqawsqps.exe
- %WINDIR%\Temp\pclvivam3gucbmh.exe
- <DRIVERS>\etc\hosts
- %TEMP%\pclvivam3026bmhckp2nqdj.exe
- 'th###ail.net':80
- 'dr###mail.net':80
- 'dr###wore.net':80
- 'dr###where.net':80
- 'th###ore.net':80
- 'th###oad.net':80
- 'fa###ore.net':80
- 'wa###wore.net':80
- 'wa###where.net':80
- 'dr###road.net':80
- 'fa###here.net':80
- 'th###here.net':80
- 'so###hand.net':80
- 'ar###hand.net':80
- 'up###ift.net':80
- 'up###reen.net':80
- 'wh###lift.net':80
- 'so###sound.net':80
- 'so###lift.net':80
- 'ar###lift.net':80
- 'ar###green.net':80
- 'ar###sound.net':80
- 'so###green.net':80
- 'eq###wore.net':80
- 'gr###mail.net':80
- 'gr###wore.net':80
- 'gr###where.net':80
- 'eq###where.net':80
- 'eq###mail.net':80
- 'af###sllc.com':80
- 'ri###nstorm.net':80
- 'be##lxc.com':80
- 'gr###road.net':80
- 'de###lxc.com':80
- 'sp###road.net':80
- 'wa###road.net':80
- 'vi###where.net':80
- 'fa###oad.net':80
- 'fa###ail.net':80
- 'wa###mail.net':80
- 'sp###where.net':80
- 'sp###mail.net':80
- 'vi###road.net':80
- 'vi###mail.net':80
- 'vi###wore.net':80
- 'sp###wore.net':80
- http://th###ail.net/index.php
- http://dr###mail.net/index.php
- http://dr###wore.net/index.php
- http://dr###where.net/index.php
- http://th###ore.net/index.php
- http://th###oad.net/index.php
- http://fa###ore.net/index.php
- http://wa###wore.net/index.php
- http://wa###where.net/index.php
- http://dr###road.net/index.php
- http://fa###here.net/index.php
- http://th###here.net/index.php
- http://so###hand.net/index.php
- http://ar###hand.net/index.php
- http://up###ift.net/index.php
- http://up###reen.net/index.php
- http://wh###lift.net/index.php
- http://so###sound.net/index.php
- http://so###lift.net/index.php
- http://ar###lift.net/index.php
- http://ar###green.net/index.php
- http://ar###sound.net/index.php
- http://so###green.net/index.php
- http://eq###wore.net/index.php
- http://gr###mail.net/index.php
- http://gr###wore.net/index.php
- http://gr###where.net/index.php
- http://eq###where.net/index.php
- http://eq###mail.net/index.php
- http://af###sllc.com/index.php
- http://ri###nstorm.net/index.php
- http://be##lxc.com/index.php
- http://gr###road.net/index.php
- http://de###lxc.com/index.php
- http://sp###road.net/index.php
- http://wa###road.net/index.php
- http://vi###where.net/index.php
- http://fa###oad.net/index.php
- http://fa###ail.net/index.php
- http://wa###mail.net/index.php
- http://sp###where.net/index.php
- http://sp###mail.net/index.php
- http://vi###road.net/index.php
- http://vi###mail.net/index.php
- http://vi###wore.net/index.php
- http://sp###wore.net/index.php
- DNS ASK dr###wore.net
- DNS ASK th###ail.net
- DNS ASK dr###mail.net
- DNS ASK th###here.net
- DNS ASK dr###where.net
- DNS ASK th###ore.net
- DNS ASK wa###where.net
- DNS ASK fa###ore.net
- DNS ASK wa###wore.net
- DNS ASK th###oad.net
- DNS ASK dr###road.net
- DNS ASK fa###here.net
- DNS ASK up###ift.net
- DNS ASK so###hand.net
- DNS ASK ar###hand.net
- DNS ASK wh###green.net
- DNS ASK up###reen.net
- DNS ASK wh###lift.net
- DNS ASK ar###green.net
- DNS ASK so###lift.net
- DNS ASK ar###lift.net
- DNS ASK so###sound.net
- DNS ASK ar###sound.net
- DNS ASK so###green.net
- DNS ASK eq###wore.net
- DNS ASK gr###mail.net
- DNS ASK gr###wore.net
- DNS ASK gr###where.net
- DNS ASK eq###where.net
- DNS ASK eq###mail.net
- DNS ASK af###sllc.com
- DNS ASK ri###nstorm.net
- DNS ASK be##lxc.com
- DNS ASK gr###road.net
- DNS ASK de###lxc.com
- DNS ASK sp###road.net
- DNS ASK wa###road.net
- DNS ASK vi###where.net
- DNS ASK fa###oad.net
- DNS ASK fa###ail.net
- DNS ASK wa###mail.net
- DNS ASK sp###where.net
- DNS ASK sp###mail.net
- DNS ASK vi###road.net
- DNS ASK vi###mail.net
- DNS ASK vi###wore.net
- DNS ASK sp###wore.net
- '23#.#55.255.250':1900