Technical Information
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Run' = '%TEMP%\sudew.exe'
- illcvlxn.exe process, Amsi.dll module
- sudew.exe process, Amsi.dll module
- %TEMP%\golfinfo.ini
- %TEMP%\sudew.exe
- %TEMP%\_sannuy.bat
- '%TEMP%\sudew.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\_sannuy.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\_sannuy.bat" "' (with hidden window)