Technical Information
- <SYSTEM32>\tasks\updater
- %TEMP%\content\4744-3160-<File name>.exe-08-30-23-301.dump
- %TEMP%\content\4744-3160-<File name>.exe-08-30-24-549.dump
- %APPDATA%\temp\updater.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- %TEMP%\content\972-856-updater.exe-08-30-28-041.dump
- %TEMP%\content\972-856-updater.exe-08-30-28-198.dump
- %APPDATA%\temp\updater.exe
- 'pa###bin.com':443
- '60.##5.216.60':9117
- 'pa###bin.com':443
- DNS ASK pa###bin.com
- '%APPDATA%\temp\updater.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "Updater" /sc ONLOGON /tr "%APPDATA%\temp\Updater.exe" /rl HIGHEST /f