Technical Information
- <SYSTEM32>\tasks\qtagent_40
- %WINDIR%\tasks\servicehub controller.job
- <SYSTEM32>\tasks\servicehub controller
- %WINDIR%\syswow64\comp.exe
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\ce10efb3
- %TEMP%\ceb1aae6
- %APPDATA%\tlsserver\bitb78b.tmp
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_0cb67e2f-dc95-45ca-8fb8-69bde8e3f814
- %TEMP%\wymjoewye
- %APPDATA%\tlsserver\bitb78b.tmp
- from %APPDATA%\tlsserver\bitb78b.tmp to %APPDATA%\tlsserver\qtagent_40.exe
- 'mo######tral-petparade.com':80
- http://mo######tral-petparade.com/g9jvjfd73/index.php
- DNS ASK mo######tral-petparade3.com
- DNS ASK mo######tral-petparade.com
- DNS ASK mo######tral-petparade2.com
- '%WINDIR%\syswow64\comp.exe'
- '%WINDIR%\syswow64\explorer.exe'