Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'syncserver' = '<Full path to file>'
- %WINDIR%\syswow64\cmd.exe
- %LOCALAPPDATA%\microsoft vision\2023-11-13_14.56.52
- 'fu######hebone.giize.com':5132
- 'fu######hebone.giize.com':5132
- DNS ASK fu######hebone.giize.com
- '%WINDIR%\syswow64\cmd.exe'