Technical Information
- 'UserUpdateSvc' %TEMP%\svchost_1770509843.exe
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\mozilla\firefox\profiles.ini
- %TEMP%\svchost_1770509843.exe
- nul
- 'ap#.##legram.org':443
- 'ap#.##legram.org':443
- DNS ASK ap#.##legram.org
- '%TEMP%\svchost_1770509843.exe'
- '%WINDIR%\syswow64\sc.exe' create UserUpdateSvc binPath= %TEMP%\svchost_1770509843.exe start= auto obj= .\\LocalSystem
- '%WINDIR%\syswow64\cmdkey.exe' /list
- '%WINDIR%\syswow64\netsh.exe' wlan show profiles
- '%TEMP%\svchost_1770509843.exe' ' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' create UserUpdateSvc binPath= %TEMP%\svchost_1770509843.exe start= auto obj= .\\LocalSystem' (with hidden window)
- '%WINDIR%\syswow64\cmdkey.exe' /list' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' wlan show profiles' (with hidden window)