Technical Information
- <SYSTEM32>\tasks\microsoft\windows\mui\l
- %APPDATA%\microsoft\launcher.exe
- %TEMP%\ba2a.tmp.exe
- http://ho##as5.ml/click.php?cn#######################
- http://ip##pi.com/xml
- http://os##oft.com/20190118/things.xml
- http://go#####analytics.com/collect
- DNS ASK ho##as5.ml
- DNS ASK ip##pi.com
- DNS ASK go#####analytics.com
- DNS ASK os##oft.com
- DNS ASK li#####.##-us-west-2.amazonaws.com
- '%TEMP%\ba2a.tmp.exe'