Technical Information
- [HKLM\System\CurrentControlSet\Services\yhVbYE6V1] 'ImagePath' = '<DRIVERS>\yhVbYE6V1.sys'
- [HKLM\System\CurrentControlSet\Services\yhVbYE6V] 'ImagePath' = '<DRIVERS>\yhVbYE6V.sys'
- 'yhVbYE6V1' <DRIVERS>\yhVbYE6V1.sys
- 'yhVbYE6V' <DRIVERS>\yhVbYE6V.sys
- %TEMP%\wgsusfrqzg34.sys
- %TEMP%\wgsusfrqzg34.exe
- <DRIVERS>\yhvbye6v.sys
- <DRIVERS>\yhvbye6v1.sys
- <DRIVERS>\yhvbye6v.sys
- <DRIVERS>\yhvbye6v1.sys
- %TEMP%\wgsusfrqzg34.sys
- %TEMP%\wgsusfrqzg34.exe
- 'mo#####.map.fastly.net':443
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK mo#####.map.fastly.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '%TEMP%\wgsusfrqzg34.exe' "%TEMP%\wgsusfrqzg34.sys"
- '%TEMP%\wgsusfrqzg34.exe' "%TEMP%\wgsusfrqzg34.sys"' (with hidden window)