Technical Information
- <SYSTEM32>\tasks\nvngxupdatecheckdaily_{5d7c6d5b-6d5b-6d5b-6d5b-5d7c6d5b6d5b}
- %WINDIR%\explorer.exe
- %TEMP%\9a26.tmp
- %APPDATA%\cjehciw
- %APPDATA%\cjehciw
- %TEMP%\9a26.tmp
- %TEMP%\9a26.tmp
- 'xi###orn.com':80
- 'ka##uelo.co':80
- 'pi###slel.is':80
- 'da##e.to':80
- '3r##amp.ga':80
- 'th##rd.ml':80
- http://xi###orn.com/
- http://ka##uelo.co/
- http://pi###slel.is/
- http://da##e.to/
- http://3r##amp.ga/
- http://th##rd.ml/
- DNS ASK xi###orn.com
- DNS ASK ka##uelo.co
- DNS ASK pi###slel.is
- DNS ASK da##e.to
- DNS ASK 3r##amp.ga
- DNS ASK th##rd.ml
- '%APPDATA%\cjehciw'
- '%APPDATA%\cjehciw' ' (with hidden window)
- '<SYSTEM32>\taskeng.exe' {A364FBDC-658A-454F-BEE4-96AB206F4B52} S-1-5-21-1960123792-2022915161-3775307078-1001:tmewpyjbeohl\user:Interactive:[1]