Technical Information
- <SYSTEM32>\tasks\ithealthmonitor
- <SYSTEM32>\windowspowershell\v1.0\client_log.txt
- %ProgramFiles%\ithealthmonitor\<File name>.exe
- nul
- %APPDATA%\systemprofile\config.dat
- <SYSTEM32>\client_log.txt
- 'it####thmonitor.app':443
- 'ge#.#eojs.io':443
- 'it####thmonitor.app':443
- 'ge#.#eojs.io':443
- DNS ASK it####thmonitor.app
- DNS ASK ge#.#eojs.io
- '%ProgramFiles%\ithealthmonitor\<File name>.exe'
- '<SYSTEM32>\schtasks.exe' /Delete /TN ITHealthMonitor /F
- '<SYSTEM32>\schtasks.exe' /Create /SC MINUTE /MO 2 /TN ITHealthMonitor /TR "\"%ProgramFiles%\ITHealthMonitor\<File name>.exe\"" /F /RL HIGHEST
- '<SYSTEM32>\schtasks.exe' /Delete /TN ITHealthMonitor /F' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /Create /SC MINUTE /MO 2 /TN ITHealthMonitor /TR "\"%ProgramFiles%\ITHealthMonitor\<File name>.exe\"" /F /RL HIGHEST' (with hidden window)