Technical Information
- %WINDIR%\tasks\taskpacing.job
- <SYSTEM32>\tasks\taskpacing
- [<HKLM>\System\CurrentControlSet\Services\Secular Fear] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Secular Fear] 'ImagePath' = '%APPDATA%\Secular Fear\Secular Fear.exe'
- 'Secular Fear' %APPDATA%\Secular Fear\Secular Fear.exe
- %ALLUSERSPROFILE%\{c8bcf1ac-2ef3-e100-c8bc-cf1ac2efc6b0}\<File name>.exe
- %ALLUSERSPROFILE%\{c8bcf1ac-2ef3-e100-c8bc-cf1ac2efc6b0}\<File name>.dat
- %APPDATA%\secular fear\secular fear.exe
- %APPDATA%\secular fear\2xf.dat
- 'fi####usapro.info':80
- 'ge####ltiple.link':80
- 'ge####uesee.info':80
- DNS ASK fi####usapro.info
- DNS ASK al####el-pro.com
- DNS ASK ge####ltiple.link
- DNS ASK ge####uesee.info
- '%APPDATA%\secular fear\secular fear.exe'