Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\defendersecurity.vbs
- %TEMP%\setup.exe
- %APPDATA%\defendersecurity.exe
- %TEMP%\is-tk1sh.tmp\setup.tmp
- %TEMP%\is-lu9ti.tmp\_isetup\_setup64.tmp
- %TEMP%\is-lu9ti.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-lu9ti.tmp\idp.dll
- %TEMP%\is-lu9ti.tmp\isdone.dll
- %LOCALAPPDATA%\microsoft\penworkspace\discovercachedata.dat
- '5.###.159.153':1151
- '%TEMP%\setup.exe'
- '%TEMP%\is-tk1sh.tmp\setup.tmp' /SL5="$B01C4,1484696,338944,%TEMP%\Setup.exe"