Technical Information
- <SYSTEM32>\tasks\mzsqsgbf
- <SYSTEM32>\tasks\syncroot
- %WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe
- %TEMP%\content\1940-3824-<File name>.exe-19-59-54-745.dump
- %TEMP%\content\1940-3824-<File name>.exe-19-59-56-456.dump
- %TEMP%\content\1940-3824-<File name>.exe-19-59-56-494.dump
- %TEMP%\content\1940-3824-<File name>.exe-20-00-08-352.dump
- %APPDATA%\membertype\syncroot.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- %TEMP%\content\2776-1408-syncroot.exe-20-00-43-132.dump
- %TEMP%\content\2776-1408-syncroot.exe-20-00-44-569.dump
- %TEMP%\content\2776-1408-syncroot.exe-20-00-44-592.dump
- %TEMP%\content\2776-1408-syncroot.exe-20-00-50-097.dump
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\syncroot.exe.log
- %TEMP%\content\4584-2316-regasm.exe-20-00-55-586.dump
- %TEMP%\content\4584-2316-regasm.exe-20-00-56-552.dump
- %TEMP%\content\4584-2316-regasm.exe-20-00-56-562.dump
- %APPDATA%\membertype\syncroot.exe
- <SYSTEM32>\tasks\mzsqsgbf
- '17#.#18.198.215':39001
- '17#.#18.198.215':39002
- '%APPDATA%\membertype\syncroot.exe'
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe'
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe' ' (with hidden window)