Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Client' = '%APPDATA%\Client.exe'
- %TEMP%\content\2816-2824-<File name>.exe-16-09-59-392.dump
- %APPDATA%\client.exe
- %TEMP%\winsvchost\runtimebrokerz.exe
- %TEMP%\content\3460-4168-runtimebrokerz.exe-16-10-07-409.dump
- '14#.#1.221.183':6606
- '%TEMP%\winsvchost\runtimebrokerz.exe' /wdg 2816 "<Full path to file>"