Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Layer Routing Protected Connection' = '<SYSTEM32>\bixuukfasvwv.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Fax Filtering SNMP DNS Bluetooth ActiveX Endpoint] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\mqemwpj.exe' "<SYSTEM32>\bixuukfasvwv.exe"
- '%WINDIR%\Temp\hurigbf35a4dpsur.exe' -r 50044 tcp
- '%TEMP%\hurigbf2xc3dpsurbrn1vz0.exe'
- '<SYSTEM32>\bixuukfasvwv.exe'
- <SYSTEM32>\hsaaaqyo\run
- <SYSTEM32>\hsaaaqyo\rng
- %WINDIR%\Temp\hurigbf35a4dpsur.exe
- <SYSTEM32>\hsaaaqyo\cfg
- <SYSTEM32>\mqemwpj.exe
- %TEMP%\hurigbf2xc3dpsurbrn1vz0.exe
- <SYSTEM32>\hsaaaqyo\tst
- <SYSTEM32>\bixuukfasvwv.exe
- <SYSTEM32>\hsaaaqyo\etc
- <SYSTEM32>\mqemwpj.exe
- <SYSTEM32>\bixuukfasvwv.exe
- %WINDIR%\Temp\hurigbf35a4dpsur.exe
- <DRIVERS>\etc\hosts
- %TEMP%\hurigbf2xc3dpsurbrn1vz0.exe
- 'fr####aturday.net':80
- 'of####aturday.net':80
- 'sp###tree.net':80
- 'sp###loud.net':80
- 'we###ree.net':80
- 'fr####housand.net':80
- 'fr###tree.net':80
- 'of###tree.net':80
- 'of###loud.net':80
- 'of####housand.net':80
- 'fr###loud.net':80
- 'mu###loud.net':80
- 'ya###ree.net':80
- 'ya###oud.net':80
- 'ya####ousand.net':80
- 'mu####housand.net':80
- 'mu###tree.net':80
- 'sp####housand.net':80
- 'we###oud.net':80
- 'we####ousand.net':80
- 'we####turday.net':80
- 'sp####aturday.net':80
- 'de####ousand.net':80
- 'ro####ousand.net':80
- 'ro####turday.net':80
- 'wi###ree.net':80
- 'de####turday.net':80
- 'de###oud.net':80
- 'wr####aturday.net':80
- 'ma####turday.net':80
- 'ro###ree.net':80
- 'ro###oud.net':80
- 'de###ree.net':80
- 'se####bertree.net':80
- 'jo####turday.net':80
- 'se####berloud.net':80
- 'se#####ersaturday.net':80
- 'se#####erthousand.net':80
- 'wi####turday.net':80
- 'wi###oud.net':80
- 'jo###ree.net':80
- 'jo###oud.net':80
- 'jo####ousand.net':80
- 'wi####ousand.net':80
- 'mu####aturday.net':80
- 'wi###ead.net':80
- 'jo###ile.net':80
- 'jo###ead.net':80
- 'al###being.net':80
- 'ri###nstorm.net':80
- 'wi###ile.net':80
- 'ro###han.net':80
- 'de###ead.net':80
- 'de###han.net':80
- 'jo###ing.net':80
- 'wi###ing.net':80
- 'cr#####onaraminta.net':80
- 'le###form.net':80
- 'jo####ymeasure.net':80
- 'ef###tbuilt.net':80
- 'th###while.net':80
- 'mo###ugust.net':80
- 'pr####tbottom.net':80
- 'ca####nbring.net':80
- 'mo###olor.net':80
- 'mi###hown.net':80
- 'ab###ell.net':80
- 'ha####turday.net':80
- 'hu####housand.net':80
- 'hu####aturday.net':80
- 'wr###king.net':80
- 'ma###ing.net':80
- 'ha####ousand.net':80
- 'ha###ree.net':80
- 'ya####turday.net':80
- 'hu###tree.net':80
- 'hu###loud.net':80
- 'ha###oud.net':80
- 'de###ing.net':80
- 'ro###ing.net':80
- 'ro###ile.net':80
- 'ro###ead.net':80
- 'de###ile.net':80
- 'wr###than.net':80
- 'wr###mile.net':80
- 'ma###ile.net':80
- 'ma###ead.net':80
- 'ma###han.net':80
- 'wr###read.net':80
- http://fr####aturday.net/index.php
- http://of####aturday.net/index.php
- http://sp###tree.net/index.php
- http://sp###loud.net/index.php
- http://we###ree.net/index.php
- http://fr####housand.net/index.php
- http://fr###tree.net/index.php
- http://of###tree.net/index.php
- http://of###loud.net/index.php
- http://of####housand.net/index.php
- http://fr###loud.net/index.php
- http://mu###loud.net/index.php
- http://ya###ree.net/index.php
- http://ya###oud.net/index.php
- http://ya####ousand.net/index.php
- http://mu####housand.net/index.php
- http://mu###tree.net/index.php
- http://sp####housand.net/index.php
- http://we###oud.net/index.php
- http://we####ousand.net/index.php
- http://we####turday.net/index.php
- http://sp####aturday.net/index.php
- http://de####ousand.net/index.php
- http://ro####ousand.net/index.php
- http://ro####turday.net/index.php
- http://wi###ree.net/index.php
- http://de####turday.net/index.php
- http://de###oud.net/index.php
- http://wr####aturday.net/index.php
- http://ma####turday.net/index.php
- http://ro###ree.net/index.php
- http://ro###oud.net/index.php
- http://de###ree.net/index.php
- http://se####bertree.net/index.php
- http://jo####turday.net/index.php
- http://se####berloud.net/index.php
- http://se#####ersaturday.net/index.php
- http://se#####erthousand.net/index.php
- http://wi####turday.net/index.php
- http://wi###oud.net/index.php
- http://jo###ree.net/index.php
- http://jo###oud.net/index.php
- http://jo####ousand.net/index.php
- http://wi####ousand.net/index.php
- http://mu####aturday.net/index.php
- http://wi###ead.net/index.php
- http://jo###ile.net/index.php
- http://jo###ead.net/index.php
- http://al###being.net/index.php
- http://ri###nstorm.net/index.php
- http://wi###ile.net/index.php
- http://ro###han.net/index.php
- http://de###ead.net/index.php
- http://de###han.net/index.php
- http://jo###ing.net/index.php
- http://wi###ing.net/index.php
- http://cr#####onaraminta.net/index.php
- http://le###form.net/index.php
- http://jo####ymeasure.net/index.php
- http://ef###tbuilt.net/index.php
- http://th###while.net/index.php
- http://mo###ugust.net/index.php
- http://pr####tbottom.net/index.php
- http://ca####nbring.net/index.php
- http://mo###olor.net/index.php
- http://mi###hown.net/index.php
- http://ab###ell.net/index.php
- http://ha####turday.net/index.php
- http://hu####housand.net/index.php
- http://hu####aturday.net/index.php
- http://wr###king.net/index.php
- http://ma###ing.net/index.php
- http://ha####ousand.net/index.php
- http://ha###ree.net/index.php
- http://ya####turday.net/index.php
- http://hu###tree.net/index.php
- http://hu###loud.net/index.php
- http://ha###oud.net/index.php
- http://de###ing.net/index.php
- http://ro###ing.net/index.php
- http://ro###ile.net/index.php
- http://ro###ead.net/index.php
- http://de###ile.net/index.php
- http://wr###than.net/index.php
- http://wr###mile.net/index.php
- http://ma###ile.net/index.php
- http://ma###ead.net/index.php
- http://ma###han.net/index.php
- http://wr###read.net/index.php
- DNS ASK fr####aturday.net
- DNS ASK of####aturday.net
- DNS ASK sp###tree.net
- DNS ASK sp###loud.net
- DNS ASK we###ree.net
- DNS ASK fr####housand.net
- DNS ASK fr###tree.net
- DNS ASK of###tree.net
- DNS ASK of###loud.net
- DNS ASK of####housand.net
- DNS ASK fr###loud.net
- DNS ASK mu###loud.net
- DNS ASK ya###ree.net
- DNS ASK ya###oud.net
- DNS ASK ya####ousand.net
- DNS ASK mu####housand.net
- DNS ASK mu###tree.net
- DNS ASK sp####housand.net
- DNS ASK we###oud.net
- DNS ASK we####ousand.net
- DNS ASK we####turday.net
- DNS ASK sp####aturday.net
- DNS ASK se#####ersaturday.net
- DNS ASK ro####ousand.net
- DNS ASK de###oud.net
- DNS ASK de####ousand.net
- DNS ASK de####turday.net
- DNS ASK ro####turday.net
- DNS ASK ro###oud.net
- DNS ASK ma####turday.net
- DNS ASK wr####housand.net
- DNS ASK wr####aturday.net
- DNS ASK de###ree.net
- DNS ASK ro###ree.net
- DNS ASK jo####turday.net
- DNS ASK wi####turday.net
- DNS ASK se####bertree.net
- DNS ASK se#####erthousand.net
- DNS ASK se####berloud.net
- DNS ASK jo####ousand.net
- DNS ASK jo###ree.net
- DNS ASK wi###ree.net
- DNS ASK wi###oud.net
- DNS ASK wi####ousand.net
- DNS ASK jo###oud.net
- DNS ASK mu####aturday.net
- DNS ASK wi###ead.net
- DNS ASK jo###ile.net
- DNS ASK jo###ead.net
- DNS ASK al###being.net
- DNS ASK ri###nstorm.net
- DNS ASK wi###ile.net
- DNS ASK ro###han.net
- DNS ASK de###ead.net
- DNS ASK de###han.net
- DNS ASK jo###ing.net
- DNS ASK wi###ing.net
- DNS ASK cr#####onaraminta.net
- DNS ASK le###form.net
- DNS ASK jo####ymeasure.net
- DNS ASK ef###tbuilt.net
- DNS ASK th###while.net
- DNS ASK mo###ugust.net
- DNS ASK pr####tbottom.net
- DNS ASK ca####nbring.net
- DNS ASK mo###olor.net
- DNS ASK mi###hown.net
- DNS ASK ab###ell.net
- DNS ASK ha####turday.net
- DNS ASK hu####housand.net
- DNS ASK hu####aturday.net
- DNS ASK wr###king.net
- DNS ASK ma###ing.net
- DNS ASK ha####ousand.net
- DNS ASK ha###ree.net
- DNS ASK ya####turday.net
- DNS ASK hu###tree.net
- DNS ASK hu###loud.net
- DNS ASK ha###oud.net
- DNS ASK de###ing.net
- DNS ASK ro###ing.net
- DNS ASK ro###ile.net
- DNS ASK ro###ead.net
- DNS ASK de###ile.net
- DNS ASK wr###than.net
- DNS ASK wr###mile.net
- DNS ASK ma###ile.net
- DNS ASK ma###ead.net
- DNS ASK ma###han.net
- DNS ASK wr###read.net
- '23#.#55.255.250':1900