Technical Information
- %TEMP%\<File name>.exe
- %TEMP%\download_eb86\<File name>.exe
- %TEMP%\htmlayout.dll
- %HOMEPATH%\desktop\continue <File name> download.lnk
- %TEMP%\<File name>_001676.log
- 'ma###soth.com':80
- http://www.ma###soth.com/api/cc
- http://ww##.#annesoth.com/api/cc?su#########################################
- DNS ASK ma###soth.com
- DNS ASK ww##.#annesoth.com
- '%TEMP%\<File name>.exe'
- '%TEMP%\download_eb86\<File name>.exe' --elevated