Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System monitor' = '%APPDATA%\Sysmon\Sysmon.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%APPDATA%\lCZ6d2602Xzg17o4\ljz6ufX7Fok0.exe",explorer.exe'
- %APPDATA%\Imminent\Logs\07-12-2017
- %APPDATA%\Sysmon\Sysmon.exe
- %APPDATA%\Imminent\Monitoring\network.dat
- %APPDATA%\Imminent\Monitoring\system.dat
- %APPDATA%\lCZ6d2602Xzg17o4\ljz6ufX7Fok0.exe
- <Current directory>:{31006D00-7000-5100-4400-500063003800}
- %TEMP%\8ARjp3i9hHAKOM26
- %TEMP%\0OY3YAOWC58hWYEG.exe
- <Full path to file>
- %APPDATA%\lCZ6d2602Xzg17o4\ljz6ufX7Fok0.exe
- 're####.sytes.net':9007
- DNS ASK re####.sytes.net
- '%TEMP%\is-EQSC2.tmp\0OY3YAOWC58hWYEG.tmp' /SL5="$100EE,5463920,535040,%TEMP%\0OY3YAOWC58hWYEG.exe"
- '<Full path to file>'
- '%TEMP%\0OY3YAOWC58hWYEG.exe'