Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WinHost] 'ImagePath' = '<SYSTEM32>\WinHost.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinHost] 'Start' = '00000002'
- '<SYSTEM32>\WinHost.exe'
- '<SYSTEM32>\cmd.exe' del <Full path to file> >> NUL
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\WinHost.exe
- <Full path to file>
- 'pe###nasconn.ru':443
- 've###rusural.ru':443
- 'sw###awert.com':443
- 'we###tumbahn.ru':443
- 'se####glandam.ru':443
- 're####ratormira.ru':443
- 'se####atmiru.com':443
- 'ta###zuwek.ru':443
- 'xa###pefgr.ru':443
- 'li###refa.ru':443
- 'la###leftre.ru':443
- 'mi###tubiv.ru':443
- 'we###ubaz.ru':443
- DNS ASK pe###nasconn.ru
- DNS ASK ve###rusural.ru
- DNS ASK sw###awert.com
- DNS ASK re####ratormira.ru
- DNS ASK as####rspace.com
- DNS ASK we###tumbahn.ru
- DNS ASK se####glandam.ru
- DNS ASK ta###zuwek.ru
- DNS ASK xa###pefgr.ru
- DNS ASK li###refa.ru
- DNS ASK we###ubaz.ru
- DNS ASK se####atmiru.com
- DNS ASK la###leftre.ru
- DNS ASK mi###tubiv.ru