Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Klmnop Rstuvwxy Bcd] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Klmnop Rstuvwxy Bcd] 'ImagePath' = '<SYSTEM32>\svchost.exe -k imgsvc'
- 'Klmnop Rstuvwxy Bcd' <SYSTEM32>\svchost.exe -k imgsvc
- C:\winlog.ini
- %ProgramFiles(x86)%\plmn\ulmnopqrs.bmp
- C:\winlog.ini
- C:\winlog.ini
- '0.###.ngrok.io':13445
- DNS ASK 0.###.ngrok.io
- '%WINDIR%\syswow64\rundll32.exe' "%ProgramFiles(x86)%\Plmn\Ulmnopqrs.bmp", FineView