Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '4871467F6C6BB2BA' = '%ALLUSERSPROFILE%\Client Demo\saser.exe'
- <SYSTEM32>\tasks\client demo
- %ALLUSERSPROFILE%\client demo\saser.exe
- nul
- '38.##.227.64':80
- '%ALLUSERSPROFILE%\client demo\saser.exe'
- '<SYSTEM32>\cmd.exe' /C timeout /t 3 /nobreak > Nul & Del /f /q "<Full path to file>"
- '<SYSTEM32>\timeout.exe' /t 3 /nobreak