Technical Information
- <SYSTEM32>\cryptowinrt.exe
- nul
- '<LOCALNET>.116.9':8080
- '<SYSTEM32>\cryptowinrt.exe'
- '<SYSTEM32>\cmd.exe' /C timeout /t 1 > nul & del "<Full path to file>"
- '<SYSTEM32>\schtasks.exe' /create /tn "uEAINTkTPmA" /tr "u dnSUXRIL;00 +tz 95=: 8<" /sc onlogon /ru "SYSTEM" /rl HIGHEST /f
- '<SYSTEM32>\timeout.exe' /t 1