Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Support Service' = '%TEMP%\\RuntimeBroker.exe'
- <SYSTEM32>\fontdrvhost.exe
- %TEMP%\runtimebroker.exe
- '45.##.66.164':4445
- '<SYSTEM32>\fontdrvhost.exe'
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\cmd.exe' ' (with hidden window)