Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] '<File name>' = '<Full path to file>'
- %LOCALAPPDATA%\178bfbff000406f1
- <PATH_SAMPLE>.data
- %TEMP%\88h2mk6w4b240384b95\np1v8.exe
- %TEMP%\88h2mk6w4b240384b95\2lz9b7x5616nfzn2zqev47bp46.exe
- %TEMP%\88h2mk6w4b240384b95\2lz9b7x5616nfzn2zqev47bp46.data
- '10#.#05.6.21':9999
- '10#.#05.6.21':9999
- '%TEMP%\88h2mk6w4b240384b95\np1v8.exe'
- '%TEMP%\88h2mk6w4b240384b95\2lz9b7x5616nfzn2zqev47bp46.exe'