Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'raadstu' = '%TEMP%\markssub\TARZ.vbs'
- tarz.exe
- hydhvv.exe process, ntdll.dll module
- tarz.exe process, ntdll.dll module
- %TEMP%\markssub\tarz.exe
- %TEMP%\markssub\tarz.vbs
- 'drive.google.com':443
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?dd##############
- 'drive.google.com':443
- DNS ASK drive.google.com
- '%TEMP%\markssub\tarz.exe'