Technical Information
- <SYSTEM32>\tasks\syshiddentask
- '%TEMP%\svchost.exe'
- '<SYSTEM32>\taskkill.exe' /F /IM wscript.exe
- %TEMP%\svchost.exe
- %TEMP%\svchost.exe
- 'localhost':7000
- ClassName: '' WindowName: ''
- '<SYSTEM32>\attrib.exe' +H +S "%TEMP%\svchost.exe"
- '<SYSTEM32>\schtasks.exe' /create /tn SysHiddenTask /tr "%TEMP%\svchost.exe" /sc ONLOGON /RL HIGHEST /F
- '<SYSTEM32>\schtasks.exe' /run /tn SysHiddenTask
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM wscript.exe
- '<SYSTEM32>\taskeng.exe' {FF4E3E90-0E58-4AA6-A53E-16624A06FC54} S-1-5-21-3691498038-2086406363-2140527554-1000:jqgmkjuxvbsp\user:Interactive:[1]
- '<SYSTEM32>\attrib.exe' +H +S "%TEMP%\svchost.exe"' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /tn SysHiddenTask /tr "%TEMP%\svchost.exe" /sc ONLOGON /RL HIGHEST /F' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /run /tn SysHiddenTask' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM wscript.exe' (with hidden window)
- '%TEMP%\svchost.exe' ' (with hidden window)