Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe
- %TEMP%\aa5c107bb257757b8206731733e7baae\chromium_cookies_lvxhbj_2025-12-01_09.25.41.json
- %TEMP%\aa5c107bb257757b8206731733e7baae\gecko_cookies_lvxhbj_2025-12-01_09.25.45.json
- %TEMP%\aa5c107bb257757b8206731733e7baae\screenshot_lvxhbj_2025-12-01_09.25.46.png
- %TEMP%\aa5c107bb257757b8206731733e7baae\chromium_cookies_lvxhbj_2025-12-01_09.25.41.json
- %TEMP%\aa5c107bb257757b8206731733e7baae\gecko_cookies_lvxhbj_2025-12-01_09.25.45.json
- %TEMP%\aa5c107bb257757b8206731733e7baae\screenshot_lvxhbj_2025-12-01_09.25.46.png
- 'ic###azip.com':80
- 'ma##.##ikei-rmc-co.biz':587
- 'x1.#.lencr.org':80
- http://ic###azip.com/
- http://x1.#.lencr.org/
- 'ma##.##ikei-rmc-co.biz':587
- DNS ASK ic###azip.com
- DNS ASK ma##.##ikei-rmc-co.biz
- DNS ASK x1.#.lencr.org
- '%WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe'