Technical Information
- %WINDIR%\tasks\xcfiknp.job
- <SYSTEM32>\tasks\xcfiknp
- %ALLUSERSPROFILE%\mwhr\xcfiknp.exe
- %WINDIR%\tasks\xcfiknp.job
- <SYSTEM32>\tasks\xcfiknp
- %ALLUSERSPROFILE%\mwhr\xcfiknp.exe
- 'sd###ert197.com':4044
- DNS ASK sd###ert197.com
- '%ALLUSERSPROFILE%\mwhr\xcfiknp.exe' start
- '%ALLUSERSPROFILE%\mwhr\xcfiknp.exe' start' (with hidden window)
- '%WINDIR%\temp\oetjaof.exe' ' (with hidden window)