Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '5aa7e59ab08a20c2fa7af28c19bcd95e' = '"%APPDATA%\winhost.exe" ..'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] '5aa7e59ab08a20c2fa7af28c19bcd95e' = '"%APPDATA%\winhost.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\5aa7e59ab08a20c2fa7af28c19bcd95e.exe
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%APPDATA%\winhost.exe" "winhost.exe" ENABLE
- %TEMP%\aut7ca4.tmp
- %TEMP%\winhostx86.exe
- %TEMP%\aut7cd4.tmp
- %TEMP%\bitcoinminer.exe
- %APPDATA%\winhost.exe
- %TEMP%\aut7ca4.tmp
- %TEMP%\aut7cd4.tmp
- 'vi########dio-compiler.myq-see.com':4444
- DNS ASK vi########dio-compiler.myq-see.com
- '%TEMP%\winhostx86.exe'
- '%TEMP%\bitcoinminer.exe'
- '%APPDATA%\winhost.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%APPDATA%\winhost.exe" "winhost.exe" ENABLE' (with hidden window)