Technical Information
- [HKLM\System\CurrentControlSet\Services\Rsmcsf iuwghibs] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Rsmcsf iuwghibs] 'ImagePath' = '<SYSTEM32>\uyaoye.exe'
- 'Rsmcsf iuwghibs' <SYSTEM32>\uyaoye.exe
- %WINDIR%\syswow64\uyaoye.exe
- %WINDIR%\syswow64\uyaoye.exe
- '98.##9.99.206':5874
- 'hf###azai.xyz':2044
- DNS ASK hf###azai.xyz
- '%WINDIR%\syswow64\uyaoye.exe'