Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'dangcap161' = 'rundll32.exe "%APPDATA%\Microsoft\hazz161.dll",UpdateCheck'
- %WINDIR%\explorer.exe
- explorer.exe process, Amsi.dll module
- %APPDATA%\microsoft\hazz161.dll
- '10#.#8.109.161':56005