Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '¸ßÇåÎúÒôƵ¹ÜÀГÆ÷' = 'C:\Users\Public\Documents\Windows\RuntimeBroker.exe'
- C:\users\public\documents\windows\runtimebroker.exe
- C:\users\public\documents\windows\runtimebroker.exe
- '10#.#31.14.104':80
- '10#.#31.14.104':83
- http://10#.#31.14.104/www
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- 'C:\users\public\documents\windows\runtimebroker.exe'
- 'C:\users\public\documents\windows\runtimebroker.exe' ' (with hidden window)