Technical Information
- %WINDIR%\syswow64\rundll32.exe
- %TEMP%\cleanup23.dll
- %TEMP%\msteamssetup_c_l_.exe
- %LOCALAPPDATA%\squirreltemp\background.gif
- %LOCALAPPDATA%\squirreltemp\downloading.gif
- %LOCALAPPDATA%\squirreltemp\endpoint.json
- %LOCALAPPDATA%\squirreltemp\update.exe
- 're####ectyourman.eu':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 're####ectyourman.eu':443
- DNS ASK re####ectyourman.eu
- DNS ASK x1.#.lencr.org
- '%TEMP%\msteamssetup_c_l_.exe'
- '%TEMP%\msteamssetup_c_l_.exe' --rerunningWithoutUAC
- '%LOCALAPPDATA%\squirreltemp\update.exe' --install . --rerunningWithoutUAC --exeName=MSTeamsSetup_c_l_.exe --bootstrapperMode
- '%TEMP%\msteamssetup_c_l_.exe' ' (with hidden window)
- '%TEMP%\msteamssetup_c_l_.exe' --rerunningWithoutUAC' (with hidden window)
- '<SYSTEM32>\rundll32.exe' %TEMP%\CleanUp23.dll,Test