Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdate' = '%APPDATA%\OneDriveStarter.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'OneDriveStarter' = '%LOCALAPPDATA%\RuntimeBrokerSrv.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'GoogleUpdateCore' = '%ALLUSERSPROFILE%\csrsss.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdate' = '<Full path to file>'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdate' = '<Full path to file>'
- <SYSTEM32>\tasks\windowsupdatetask
- %APPDATA%\microsoft\windows\start menu\programs\startup\svchost.exe
- xlthsuy.exe process, Amsi.dll module
- xlthsuy.exe process, ntdll.dll module
- %APPDATA%\onedrivestarter.exe
- %LOCALAPPDATA%\runtimebrokersrv.exe
- %ALLUSERSPROFILE%\csrsss.exe
- %HOMEPATH%\winupd.exe
- %APPDATA%\microsoft\windows\start menu\svchost.exe
- %WINDIR%\googleupdatecore.exe
- %TEMP%\googleupdatecore.exe
- %APPDATA%\microsoft\svchost.exe
- %APPDATA%\onedrivestarter.exe
- %LOCALAPPDATA%\runtimebrokersrv.exe
- %ALLUSERSPROFILE%\csrsss.exe
- %HOMEPATH%\winupd.exe
- %APPDATA%\microsoft\windows\start menu\svchost.exe
- %WINDIR%\googleupdatecore.exe
- %TEMP%\googleupdatecore.exe
- %APPDATA%\microsoft\windows\start menu\programs\startup\svchost.exe
- %APPDATA%\microsoft\svchost.exe
- 'ap#.##legram.org':443
- DNS ASK ap#.##legram.org
- '%APPDATA%\onedrivestarter.exe'
- '%LOCALAPPDATA%\runtimebrokersrv.exe'
- '%ALLUSERSPROFILE%\csrsss.exe'
- '%HOMEPATH%\winupd.exe'
- '%APPDATA%\microsoft\windows\start menu\svchost.exe'
- '%WINDIR%\googleupdatecore.exe'
- '%TEMP%\googleupdatecore.exe'
- '<SYSTEM32>\cmd.exe' /c wevtutil cl System && wevtutil cl Security && wevtutil cl Application
- '<SYSTEM32>\wevtutil.exe' cl System
- '<SYSTEM32>\wevtutil.exe' cl Security
- '<SYSTEM32>\wevtutil.exe' cl Application
- '<SYSTEM32>\schtasks.exe' /create /tn "WindowsUpdateTask" /tr "<Full path to file>" /sc onlogon /f
- '%APPDATA%\onedrivestarter.exe' ' (with hidden window)
- '%LOCALAPPDATA%\runtimebrokersrv.exe' ' (with hidden window)
- '%ALLUSERSPROFILE%\csrsss.exe' ' (with hidden window)
- '%HOMEPATH%\winupd.exe' ' (with hidden window)
- '%APPDATA%\microsoft\windows\start menu\svchost.exe' ' (with hidden window)
- '%WINDIR%\googleupdatecore.exe' ' (with hidden window)
- '%TEMP%\googleupdatecore.exe' ' (with hidden window)