Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\srserviceSysmonLog] 'Start' = '00000002'
- '<SYSTEM32>\apcupsv.exe'
- '<SYSTEM32>\svchost.exe' "<SYSTEM32>\apcupsv.exe"
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\ansie.exe
- <SYSTEM32>\322299313.dat
- <SYSTEM32>\alrsvco.exe
- <SYSTEM32>\advapi32r.exe
- <SYSTEM32>\apcupsv.exe
- <SYSTEM32>\apcupsv.exe
- <SYSTEM32>\ansie.exe
- <SYSTEM32>\alrsvco.exe
- <SYSTEM32>\advapi32r.exe
- '23#.#55.255.250':1900