Technical Information
- [<HKLM>\software\Wow6432Node\microsoft\windows\CurrentVersion\Run] 'neme' = 'D:\ub\lasaa.exe'
- <SYSTEM32>\tasks\î¢èГ
- lasaa.exe
- D:\ub\lasaa.exe
- D:\ub\md5.png
- D:\ub\autoip.dll
- '10#.#49.107.30':8000
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- 'D:\ub\lasaa.exe'
- '%WINDIR%\syswow64\cmd.exe' /c cmd.exe /c SCHTASKS /Create /SC ONSTART /TN "ГЋВўГ€Г" /TR "D:\ub\lasaa.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cmd.exe /c SCHTASKS /Create /SC ONSTART /TN "ГЋВўГ€Г" /TR "D:\ub\lasaa.exe"
- '%WINDIR%\syswow64\cmd.exe' /c SCHTASKS /Create /SC ONSTART /TN "ГЋВўГ€Г" /TR "D:\ub\lasaa.exe"
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC ONSTART /TN "ГЋВўГ€Г" /TR "D:\ub\lasaa.exe"