Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WinUpdate Service] 'ImagePath' = 'cmd.exe /c start %ALLUSERSPROFILE%\Application Data\{31D0884A-AEBA-3C6D-4D80-9E5EE31D851E}\9C6F58D5.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinUpdate Service] 'Start' = '00000002'
- %TEMP%\0C0FC2F21.tmp
- %APPDATA%\state.tmp
- %ALLUSERSPROFILE%\Application Data\{31D0884A-AEBA-3C6D-4D80-9E5EE31D851E}\9C6F58D5.exe
- <Current directory>\logfile.txt
- %ALLUSERSPROFILE%\Application Data\salt.dat
- <Full path to file>
- '86.#9.21.38':443
- '52.##.214.72':443
- 'ip##fo.io':80
- 'localhost':1036
- '13#.#88.40.189':443
- 'ip##fo.io':443
- http://ip##fo.io/
- DNS ASK ip##fo.io
- ClassName: '0' WindowName: ''
- ClassName: 'SysTreeView32' WindowName: ''
- ClassName: 'l?' WindowName: ''
- ClassName: 'lф' WindowName: ''
- '<SYSTEM32>\sc.exe' create "WinUpdate Service" binPath= "cmd.exe /c start %ALLUSERSPROFILE%\Application Data\{31D0884A-AEBA-3C6D-4D80-9E5EE31D851E}\9C6F58D5.exe" type= own start= auto error= ignore
- '<SYSTEM32>\svchost.exe'