Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SysHelper' = '"<LS_APPDATA>\7ce4257e-13fa-4016-8d43-1ecc6a47a39e\<File name>.exe" --AutoStart'
- <SYSTEM32>\tasks\time trigger task
- <LS_APPDATA>\7ce4257e-13fa-4016-8d43-1ecc6a47a39e\<File name>.exe
- <SYSTEM32>\tasks\time trigger task
- DNS ASK ap#.2ip.ua
- DNS ASK br##e2.ug
- '%WINDIR%\syswow64\icacls.exe' "<LS_APPDATA>\7ce4257e-13fa-4016-8d43-1ecc6a47a39e" /deny *S-1-1-0:(OI)(CI)(DE,DC)' (with hidden window)
- '%WINDIR%\syswow64\icacls.exe' "<LS_APPDATA>\7ce4257e-13fa-4016-8d43-1ecc6a47a39e" /deny *S-1-1-0:(OI)(CI)(DE,DC)