Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Client Server Runtime Process' = '%LOCALAPPDATA%\csr_hostsvc.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath '%LOCALAPPDATA%'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- %LOCALAPPDATA%\csr_hostsvc.exe
- %TEMP%\evbc8df.tmp
- %TEMP%\evbc8ff.tmp
- %LOCALAPPDATA%\screenshot.png
- %LOCALAPPDATA%\csr_hostsvc.exe
- %LOCALAPPDATA%\screenshot.png
- 'ap#.#pify.org':443
- 'ap#.##legram.org':443
- 'ap#.#pify.org':443
- 'ap#.##legram.org':443
- DNS ASK ap#.#pify.org
- DNS ASK ap#.##legram.org
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- ClassName: 'File Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: 'Process Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- '%LOCALAPPDATA%\csr_hostsvc.exe'
- '%WINDIR%\syswow64\cmd.exe' /c start "" "%LOCALAPPDATA%\csr_hostsvc.exe"