Technical Information
- [<HKLM>\System\CurrentControlSet\Services\ServiceKMS] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ServiceKMS] 'ImagePath' = '<SYSTEM32>\svchost.exe -k ServiceKMS'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\ServiceKMS\Parameters] 'ServiceDll' = '<SYSTEM32>\Service_KMS.dll'
- 'ServiceKMS' <SYSTEM32>\svchost.exe -k ServiceKMS
- '<SYSTEM32>\taskkill.exe' /pid 3052 /t
- <SYSTEM32>\service_kms.dll
- <SYSTEM32>\log\20210304_1180.log
- DNS ASK sa##.onpxe.com
- '255.255.255.255':56717
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c taskkill /pid 3052 /t & del /s /q "<Full path to file>"' (with hidden window)
- '<SYSTEM32>\svchost.exe' -k ServiceKMS
- '<SYSTEM32>\cmd.exe' /c taskkill /pid 3052 /t & del /s /q "<Full path to file>"