Technical Information
- [HKCU\Environment] 'UserInitMprLogonScript' = '"%LOCALAPPDATA%\873513a0deff439d958f4ffc7967a705\<File name>.exe"'
- %LOCALAPPDATA%\873513a0deff439d958f4ffc7967a705\<File name>.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<File name>.exe.log
- 'sy#######elemetry.duckdns.org':4444
- 'sy#######elemetry.duckdns.org':4444
- DNS ASK sy#######elemetry.duckdns.org
- '%LOCALAPPDATA%\873513a0deff439d958f4ffc7967a705\<File name>.exe'