Technical Information
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Run' = '%TEMP%\sopea.exe'
- qwzvpvn.exe process, Amsi.dll module
- sopea.exe process, Amsi.dll module
- %TEMP%\golfinfo.ini
- %TEMP%\sopea.exe
- %TEMP%\_uinsey.bat
- '%TEMP%\sopea.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\_uinsey.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\_uinsey.bat" "' (with hidden window)