Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{PXS91NV7-618910-WDZ9GU-WDZ9GUB7FR}' = '"%TEMP%\svchost.exe" ...'
- %HOMEPATH%\Start Menu\Programs\Startup\{PXS91NV7-618910-WDZ9GU-WDZ9GUB7FR}.exe
- hidden files
- '%TEMP%\svchost.exe'
- %TEMP%\svchost.exe
- %HOMEPATH%\Start Menu\Programs\Startup\{PXS91NV7-618910-WDZ9GU-WDZ9GUB7FR}.exe
- %TEMP%\svchost.exe
- 'ka##8.xyz':5552
- DNS ASK ka##8.xyz