Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\runtimebroker.exe
- <SYSTEM32>\windowspowershell\v1.0\bot.log
- 'ap#.##legram.org':443
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7d##############
- 'ap#.##legram.org':443
- DNS ASK ap#.##legram.org