Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'e8dead83b1324d64bf63123f9fa3bd72' = '"%HOMEPATH%\servicesss.exe" ..'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'e8dead83b1324d64bf63123f9fa3bd72' = '"%HOMEPATH%\servicesss.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\e8dead83b1324d64bf63123f9fa3bd72.exe
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%HOMEPATH%\servicesss.exe" "servicesss.exe" ENABLE
- %HOMEPATH%\servicesss.exe
- 'dp##te.org':443
- 'bu#####rke.duckdns.org':4000
- DNS ASK dp##te.org
- DNS ASK bu#####rke.duckdns.org
- '%HOMEPATH%\servicesss.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%HOMEPATH%\servicesss.exe" "servicesss.exe" ENABLE' (with hidden window)