Technical Information
- <SYSTEM32>\tasks\tgmonitor
- %ALLUSERSPROFILE%\tgmonitor\tgmonitor.exe
- nul
- '%ALLUSERSPROFILE%\tgmonitor\tgmonitor.exe'
- '<SYSTEM32>\taskeng.exe' {E1E6C0CF-B89F-4BB7-B789-436D7DF2FEAB} S-1-5-21-3691498038-2086406363-2140527554-1000:xahyfsqukrwc\user:Interactive:[1]
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgACcAQwA6AFwAJwA=
- '<SYSTEM32>\cmd.exe' /c ping 127.0.0.1 -n 2 > nul & del "<Full path to file>" & if exist "<Full path to file>" (ping 127.0.0.1 -n 2 > nul & del "<Full path to file>")
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 2
- '%ALLUSERSPROFILE%\tgmonitor\tgmonitor.exe' ' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgACcAQwA6AFwAJwA=' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ping 127.0.0.1 -n 2 > nul & del "<Full path to file>" & if exist "<Full path to file>" (ping 127.0.0.1 -n 2 > nul & del "<Full path to file>")' (with hidden window)