Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WmiApSrvSys] 'ImagePath' = '%ALLUSERSPROFILE%\Application Data\Mozilla\svchost.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\WmiApSrvSys] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- <SYSTEM32>\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\UV9FXlFbb1NfWVQPBg.bin
- %ALLUSERSPROFILE%\Application Data\Mozilla\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\UV9FXlFbb1NfWVQPBg.bin
- 'sh###ghghfg.com':80
- '52.##.125.44':443
- http://sh###ghghfg.com/EdLzouYqu/BiEZY/eBYnv9/6eHhF-HZMpYRfKm9vu-M8d5CJlcNq5bkP4.bml?Fv########################################################
- DNS ASK sh###ghghfg.com