Technical Information
- '' (downloaded from the Internet)
- %APPDATA%\popo.exe
- %APPDATA%\Acr.exe
- 'ip###ger.com':443
- 'lo##ver.su':80
- 'do#####d.acronis.com':80
- http://lo##ver.su/1.exe
- http://do#####d.acronis.com/AcronisTrueImage2018_web.exe
- DNS ASK ip###ger.com
- DNS ASK lo##ver.su
- DNS ASK do#####d.acronis.com
- ClassName: 'AutoHotkey' WindowName: '<Full path to file>'
- '%APPDATA%\popo.exe'
- '%APPDATA%\Acr.exe'