Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\d8dd87e353d610780f6be71543d70c35.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\lsasss.exe" "lsasss.exe" ENABLE
- %TEMP%\lsasss.exe
- DNS ASK av###.ddns.net
- '%TEMP%\lsasss.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\lsasss.exe" "lsasss.exe" ENABLE' (with hidden window)