Technical Information
- <SYSTEM32>\tasks\name
- %WINDIR%\explorer.exe
- %TEMP%\folder\file.exe
- %TEMP%\17d691995f9d4f47a2b74bcdcd0e85fe.xml
- DNS ASK he####aze420.com
- DNS ASK 4m###l1mit.com
- DNS ASK my#####prisedesk.com
- DNS ASK ne####ka.digital
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /Create /TN name /XML "%TEMP%\17d691995f9d4f47a2b74bcdcd0e85fe.xml"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /Create /TN name /XML "%TEMP%\17d691995f9d4f47a2b74bcdcd0e85fe.xml"
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN name /XML "%TEMP%\17d691995f9d4f47a2b74bcdcd0e85fe.xml"
- '%WINDIR%\syswow64\wscript.exe'
- '%WINDIR%\syswow64\cmd.exe' del "<Full path to file>"