Technical Information
- <SYSTEM32>\cryptowinrt.exe
- nul
- DNS ASK 9Z####zh3qsu.online
- DNS ASK m1####UVtsOj.online
- DNS ASK aO####aOyTEL.online
- DNS ASK 4d####ljT3UJ.online
- '<SYSTEM32>\cryptowinrt.exe'
- '<SYSTEM32>\cmd.exe' /C timeout /t 1 > nul & del "<Full path to file>"
- '<SYSTEM32>\timeout.exe' /t 1
- '<SYSTEM32>\schtasks.exe' /create /tn "qAMEBXoPTih=" /tr "q hb_Y\VMH`nGL4$/pv519>$$ 7+1U" /sc onlogon /ru "SYSTEM" /rl HIGHEST /f