Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '21db6b077573587a4613b5741d50b1f9' = '"%PROGRAMDATA%\conhost.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '21db6b077573587a4613b5741d50b1f9' = '"%PROGRAMDATA%\conhost.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\21db6b077573587a4613b5741d50b1f9.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%PROGRAMDATA%\conhost.exe" "conhost.exe" ENABLE
- %LOCALAPPDATA%cxswmytsvb.exe
- %LOCALAPPDATA%ybmclgot_f.jpg
- %PROGRAMDATA%\conhost.exe
- 'dn#.#rweabo.xyz':8888
- DNS ASK dn#.#rweabo.xyz
- '%LOCALAPPDATA%cxswmytsvb.exe'
- '%PROGRAMDATA%\conhost.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%PROGRAMDATA%\conhost.exe" "conhost.exe" ENABLE' (with hidden window)