Technical Information
- <SYSTEM32>\tasks\d3g4ox9mpjije2q
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 1 /tn d3G4ox9MPjIJe2Q /f /tr "wscript '%TEMP%\6vVB4LNXC2Ot.js' d3G4ox9MPjIJe2Q"
- '<SYSTEM32>\taskeng.exe' {4E35BDC8-B80F-446A-B0E1-5920F02BD8A0} S-1-5-21-3150914307-1777937420-491476919-1000:xolcucn\user:Interactive:[1]
- '<SYSTEM32>\wscript.exe' "%TEMP%\6vVB4LNXC2Ot.js" d3G4ox9MPjIJe2Q
- '<SYSTEM32>\wscript.exe' "%TEMP%\6vVB4LNXC2Ot.js" d3G4ox9MPjIJe2Q' (with hidden window)