Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Updater' = '"<LS_APPDATA>\Windows Update\updater10.exe" -1 -0'
- <LS_APPDATA>\windows update\updater10.exe
- %TEMP%\996170407.exe
- %TEMP%\961084378.exe
- %TEMP%\433020785.exe
- '88.##4.27.40':1131
- DNS ASK ap#.#pify.org
- '<LS_APPDATA>\windows update\updater10.exe' \"-0\" \"-0\" \"-<Full path to file>\"
- '<SYSTEM32>\wbem\wmic.exe' process get Caption,ParentProcessId,ProcessId' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C start "<LS_APPDATA>\Windows Update\updater10.exe" "<LS_APPDATA>\Windows Update\updater10.exe" \"-0\" \"-0\" \"-<Full path to file>\"' (with hidden window)
- '<SYSTEM32>\cmd.exe' ver' (with hidden window)
- '<SYSTEM32>\wbem\wmic.exe' process get Caption,ParentProcessId,ProcessId
- '<SYSTEM32>\cmd.exe' /C start "<LS_APPDATA>\Windows Update\updater10.exe" "<LS_APPDATA>\Windows Update\updater10.exe" \"-0\" \"-0\" \"-<Full path to file>\"
- '<SYSTEM32>\cmd.exe' ver