Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\JB8HA1RZ1F1LB1H1OE2K2QG0UK0Q0WM00YO0U0AQ0TFH11Z1FV1B1H] 'ImagePath' = '%TEMP%\JB8HA1RZ1F1LB1H1OE2K2QG0UK0Q0WM00YO0U0AQ0TFH11Z1FV1B1H.dat'
- %TEMP%\JB8HA1RZ1F1LB1H1OE2K2QG0UK0Q0WM00YO0U0AQ0TFH11Z1FV1B1H.dat
- %TEMP%\myrar.exe
- %TEMP%\JB8HA1RZ1F1LB1H1OE2K2QG0UK0Q0WM00YO0U0AQ0TFH11Z1FV1B1H.dat
- '11#.#88.248.88':8666
- '<SYSTEM32>\cmd.exe' /c sc config "UxSms" start= demand
- '<SYSTEM32>\sc.exe' config "UxSms" start= demand