Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\OGCVPNOZ] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\OGCVPNOZ] 'ImagePath' = '%ALLUSERSPROFILE%\cmbpwncjehrk\qaklofxvfqzl.exe'
- 'OGCVPNOZ' %ALLUSERSPROFILE%\cmbpwncjehrk\qaklofxvfqzl.exe
- <SYSTEM32>\conhost.exe
- <SYSTEM32>\dwm.exe
- %ALLUSERSPROFILE%\cmbpwncjehrk\qaklofxvfqzl.exe
- %WINDIR%\temp\tioqjfsbszfw.sys
- 'xm#.#miners.com':2222
- DNS ASK xm#.#miners.com
- '%ALLUSERSPROFILE%\cmbpwncjehrk\qaklofxvfqzl.exe'
- '<SYSTEM32>\sc.exe' delete "OGCVPNOZ"
- '<SYSTEM32>\sc.exe' create "OGCVPNOZ" binpath= "%ALLUSERSPROFILE%\cmbpwncjehrk\qaklofxvfqzl.exe" start= "auto"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "OGCVPNOZ"
- '<SYSTEM32>\dwm.exe'