Technical Information
- '%APPDATA%\microsoft\addins\u8x4m7s6.exe'
- '<SYSTEM32>\certutil.exe' -decode %APPDATA%\Microsoft\AddIns\G6U6U9J7.txt %APPDATA%\Microsoft\AddIns\U8X4M7S6.exe
- %APPDATA%\microsoft\addins\g6u6u9j7.txt
- %APPDATA%\microsoft\addins\u8x4m7s6.exe
- '<SYSTEM32>\certutil.exe' -decode %APPDATA%\Microsoft\AddIns\G6U6U9J7.txt %APPDATA%\Microsoft\AddIns\U8X4M7S6.exe' (with hidden window)
- '%APPDATA%\microsoft\addins\u8x4m7s6.exe' ' (with hidden window)