Technical Information
- %WINDIR%\Tasks\{6AD5A78C-4656-D2CD-4AC1-6E77B9D22EB4}.job
- '%APPDATA%\eYRpILTe\ycNwIMtV\TRQuxowc\LTbDTtsFT.exe'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- <SYSTEM32>\svchost.exe
- %APPDATA%\eYRpILTe\ycNwIMtV\TRQuxowc\LTbDTtsFT.exe
- 'pr###4you.org':80
- 'fi##.#ouwprofs.com':80
- 'ne####temweb.biz':80
- DNS ASK pr###4you.org
- DNS ASK fi##.#ouwprofs.com
- DNS ASK ne####temweb.biz