Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '79aa3db2d1725d032fca6113c47b8ae3' = '"%APPDATA%\Svchost.exe" ..'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '79aa3db2d1725d032fca6113c47b8ae3' = '"%APPDATA%\Svchost.exe" ..'
- %HOMEPATH%\Start Menu\Programs\Startup\79aa3db2d1725d032fca6113c47b8ae3.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%APPDATA%\Svchost.exe' = '%APPDATA%\Svchost.exe:*:Enabled:Svchost.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram \"C:\\Documents and Settings\\%USERNAME%\\Application Data\\Svchost.exe\" \"Svchost.exe\" ENABLE
- %APPDATA%\Svchost.exe
- 'tu######ejogo.duckdns.org':5553
- DNS ASK tu######ejogo.duckdns.org
- '%APPDATA%\Svchost.exe' and Settings\\%USERNAME%\\Application Data\\Svchost.exe\"