Technical Information
- %WINDIR%\tasks\l.job
- '' (downloaded from the Internet)
- %APPDATA%\microsoft\launcher.exe
- %TEMP%\1.tmp.exe
- http://ho##as4.cf/click.php?cn#####################
- http://ip##pi.com/xml
- http://ho##pp2.cf/20190118/things.xml
- http://go#####analytics.com/collect
- DNS ASK ho##as4.cf
- DNS ASK ip##pi.com
- DNS ASK go#####analytics.com
- DNS ASK ho##pp2.cf
- DNS ASK li#####.##-us-west-2.amazonaws.com
- '%TEMP%\1.tmp.exe'