Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Qmf_BnfvbrudkwS] 'ImagePath' = '%APPDATA%\Hmdrhjjdtt.exe'
- 'Qmf_BnfvbrudkwS' %APPDATA%\Hmdrhjjdtt.exe
- %APPDATA%\hmdrhjjdtt.exe
- 'qb###.imtt.qq.com':80
- 'wu#.#mtt.qq.com':8080
- 'dl###1.qq.com':80
- 'pu##.#rowser.qq.com':8080
- 'wu#.##owser.qq.com':443
- http://dl###1.qq.com/invc/tt/QB/kvtepqdzshxxuyj4aguco.exe
- http://wu#.###t.qq.com:8080/ via wu#.#mtt.qq.com
- http://qb###.imtt.qq.com/
- 'wu#.##owser.qq.com':443
- DNS ASK qb###.imtt.qq.com
- DNS ASK wu#.#mtt.qq.com
- DNS ASK dl###1.qq.com
- DNS ASK qq.com
- DNS ASK pu##.#rowser.qq.com
- DNS ASK wu#.##owser.qq.com
- '%APPDATA%\hmdrhjjdtt.exe'