Technical Information
- <SYSTEM32>\tasks\firefox default browser agent 6c1a57754fe79a56
- %WINDIR%\explorer.exe
- %APPDATA%\hwrvehw
- %APPDATA%\hwrvehw
- 'po###ulit.org':80
- 'hu###lior.net':80
- 'bu###u55t.net':80
- 'so###tlic4.net':80
- 'no####sa5org.org':80
- 'to###olihul.net':80
- 'so####ka51hub.net':80
- http://po###ulit.org/
- http://hu###lior.net/
- http://bu###u55t.net/
- http://so###tlic4.net/
- http://no####sa5org.org/
- http://to###olihul.net/
- http://so####ka51hub.net/
- DNS ASK po###ulit.org
- DNS ASK hu###lior.net
- DNS ASK bu###u55t.net
- DNS ASK so###tlic4.net
- DNS ASK no####sa5org.org
- DNS ASK nu###jnuli.org
- DNS ASK to###olihul.net
- DNS ASK so####ka51hub.net
- '%APPDATA%\hwrvehw'
- '%APPDATA%\hwrvehw' ' (with hidden window)
- '<SYSTEM32>\taskeng.exe' {1F564F69-5BED-44B6-977F-DAB99D0176DD} S-1-5-21-1238866942-1249195528-555854008-1000:cbwtubceesq\user:Interactive:[1]