Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsSecurityUpdate' = '<Current directory>\setup.exe'
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="WindowsSecurityUpdate" dir=in action=allow program="<Current directory>\setup.exe" enable=yes
- %TEMP%\we5ya0bw.44c
- %TEMP%\victim_info.txt
- %TEMP%\we5ya0bw.44c
- 'ap#.#pify.org':443
- 'di##ord.com':443
- DNS ASK ap#.#pify.org
- DNS ASK di##ord.com
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall delete rule name="WindowsSecurityUpdate"
- '<SYSTEM32>\netsh.exe' advfirewall firewall delete rule name="WindowsSecurityUpdate"
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall firewall add rule name="WindowsSecurityUpdate" dir=in action=allow program="<Current directory>\setup.exe" enable=yes