Technical Information
- <SYSTEM32>\tasks\java updater
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\lua5.1.dll
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %PROGRAMDATA%\msvcp100.dll
- %APPDATA%\invoice template.pdf
- %PROGRAMDATA%\client.exe
- %APPDATA%\microsoft\windows\start menu\programs\invoice\quasar.lnk
- %APPDATA%\winrar\02-15-2020
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\lua5.1.dll
- '<LOCALNET>.174.1':443
- '37.##1.113.170':443
- http://ip##pi.com/json/
- DNS ASK ip##pi.com
- ClassName: 'MS_WINHELP' WindowName: ''
- '%TEMP%\_ir_sf_temp_0\irsetup.exe' __IRAOFF:1911330 "__IRAFN:<Full path to file>" "__IRCT:3" "__IRTSS:0" "__IRSID:S-1-5-21-1960123792-2022915161-3775307078-1001"
- '%PROGRAMDATA%\client.exe'
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "%APPDATA%\invoice template.pdf"
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "Java Updater" /sc ONLOGON /tr "%PROGRAMDATA%\Client.exe" /rl HIGHEST /f