Technical Information
- [HKLM\System\CurrentControlSet\Services\AIDA64Driver] 'ImagePath' = '%TEMP%\kerneld.x64'
- 'AIDA64Driver' %TEMP%\kerneld.x64
- %TEMP%\aida64.exe
- %TEMP%\7za.exe
- %TEMP%\a.7z
- %TEMP%\nsf5522.tmp\execdos.dll
- %TEMP%\lanbo.exe
- %TEMP%\nsf5522.tmp\execdos.dll
- DNS ASK mo####imagehost.com
- '%TEMP%\7za.exe' x "%TEMP%\a.7z" -pZ0aWUCpdnC -o"%TEMP%\" -aoa
- '%TEMP%\aida64.exe'
- '%TEMP%\lanbo.exe'
- '%TEMP%\7za.exe' x "%TEMP%\a.7z" -pZ0aWUCpdnC -o"%TEMP%\" -aoa' (with hidden window)