Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '4545' = '%HOMEPATH%\rgrd\455t54t.vbs'
- 455t54t.exe
- %HOMEPATH%\rgrd\455t54t.exe
- %HOMEPATH%\rgrd\455t54t.vbs
- http://su#####lifesscience.com/tslserverRAWfile_encrypted_AD7B9AF.bin
- DNS ASK su#####lifesscience.com
- '%HOMEPATH%\rgrd\455t54t.exe'