Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\XNdw-N5J7dT87NHgzcrKfAfT] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\XNdw-N5J7dT87NHgzcrKfAfT] 'ImagePath' = 'cmd /c cd /d "%LOCALAPPDATA%\assembly\dl3\70jKb\hT3ntX\rthY\" && start "" "%LOCALAPPDATA%\assembly\dl3\70jKb\hT3...
- 'XNdw-N5J7dT87NHgzcrKfAfT' cmd /c cd /d "%LOCALAPPDATA%\assembly\dl3\70jKb\hT3ntX\rthY\" && start "" "%LOCALAPPDATA%\assembly\dl3\70jKb\hT3ntX\rthY\F5ETUIPXUh5.exe"
- %TEMP%\is-o0w09hqvx2.tmp\_isetup\_setup64.tmp
- %LOCALAPPDATA%\assembly\dl3\70jkb\ht3ntx\rthy\is-osq2jf5zr5.tmp
- %LOCALAPPDATA%\assembly\dl3\70jkb\ht3ntx\rthy\is-wiektnzyof.tmp
- %LOCALAPPDATA%\assembly\dl3\70jkb\ht3ntx\rthy\is-ok20nfoqz2.tmp
- %ALLUSERSPROFILE%\e7c712b7669a452bba3fe4cf0e5eb4cf\config.ini
- %TEMP%\is-o0w09hqvx2.tmp\_isetup\_setup64.tmp
- from %LOCALAPPDATA%\assembly\dl3\70jkb\ht3ntx\rthy\is-osq2jf5zr5.tmp to %LOCALAPPDATA%\assembly\dl3\70jkb\ht3ntx\rthy\f5etuipxuh5.exe
- from %LOCALAPPDATA%\assembly\dl3\70jkb\ht3ntx\rthy\is-wiektnzyof.tmp to %LOCALAPPDATA%\assembly\dl3\70jkb\ht3ntx\rthy\jo.q
- from %LOCALAPPDATA%\assembly\dl3\70jkb\ht3ntx\rthy\is-ok20nfoqz2.tmp to %LOCALAPPDATA%\assembly\dl3\70jkb\ht3ntx\rthy\rjjad93d.e
- '10#.#43.42.209':22
- '10#.#43.42.209':22
- DNS ASK ba####aofu88.com
- '%LOCALAPPDATA%\assembly\dl3\70jkb\ht3ntx\rthy\f5etuipxuh5.exe'
- '%LOCALAPPDATA%\assembly\dl3\70jkb\ht3ntx\rthy\f5etuipxuh5.exe' ' (with hidden window)