Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\baby] 'ImagePath' = '<SYSTEM32>\PastmHbTt.sys'
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- <SYSTEM32>\PastmHbTt.sys
- <SYSTEM32>\PastmHbTt.sys
- 'www.cf###ojin.com':80
- '12#.#25.114.144':80
- http://hi.##idu.com/wipifxbfgobadpd/item/c75d881971c98d6d2a3e22a7 via 12#.#25.114.144
- http://www.cf###ojin.com/
- http://hi.##idu.com/new/xjp0595 via 12#.#25.114.144
- DNS ASK www.cf###ojin.com
- DNS ASK hi.##idu.com
- ClassName: '18467-41' WindowName: ''