Technical Information
- winhost (2).exe
- %APPDATA%\1337\winhost (2).exe
- %TEMP%\is-1U29F.tmp\vpn.tmp
- %APPDATA%\1337\vpn.exe
- %TEMP%\nsf2.tmp
- %TEMP%\nsa3.tmp\System.dll
- %TEMP%\nsa3.tmp\System.dll
- '%TEMP%\is-1U29F.tmp\vpn.tmp' /SL5="$40092,7490130,150528,%APPDATA%\1337\vpn.exe"
- '%APPDATA%\1337\winhost (2).exe'
- '%APPDATA%\1337\vpn.exe'