Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Reflector2' = '<Full path to file>'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Reflector2' = '<Full path to file>'
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.exe
- %APPDATA%\windows logs\01-26-2020
- 'localhost':9412
- http://ip##pi.com/json/
- DNS ASK ip##pi.com