Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1뭟媰‥ݎ黜랤' = '%ProgramFiles%\<File name>.exe'
- %ProgramFiles%\<File name>.exe
- %APPDATA%\explorer.exe
- %APPDATA%\lsass.exe
- %APPDATA%\filename.exe
- %ProgramFiles%\<File name>.exe
- %APPDATA%\lsass.exe
- %APPDATA%\filename.exe
- 'sm##.gmail.com':587
- DNS ASK sm##.gmail.com
- '%APPDATA%\explorer.exe'
- '%APPDATA%\lsass.exe'
- '%APPDATA%\filename.exe'