Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdateSvc' = '<Full path to file>'
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.exe
- %TEMP%\_mei54082\vcruntime140.dll
- %TEMP%\_mei54082\_bz2.pyd
- %TEMP%\_mei54082\_ctypes.pyd
- %TEMP%\_mei54082\_decimal.pyd
- %TEMP%\_mei54082\_hashlib.pyd
- %TEMP%\_mei54082\_lzma.pyd
- %TEMP%\_mei54082\_socket.pyd
- %TEMP%\_mei54082\_ssl.pyd
- %TEMP%\_mei54082\_zstd.pyd
- %TEMP%\_mei54082\base_library.zip
- %TEMP%\_mei54082\libcrypto-3.dll
- %TEMP%\_mei54082\libffi-8.dll
- %TEMP%\_mei54082\libssl-3.dll
- %TEMP%\_mei54082\python314.dll
- %TEMP%\_mei54082\select.pyd
- %TEMP%\_mei54082\unicodedata.pyd
- %ALLUSERSPROFILE%\windowsupdate\<File name>.exe.exe
- '0b#####jc7.localto.net':1490
- DNS ASK 0b#####jc7.localto.net