Technical Information
- <SYSTEM32>\tasks\svchost
- <SYSTEM32>\tasks\sihost
- %ProgramFiles(x86)%\windows portable devices\svchost.exe
- %ProgramFiles(x86)%\windowspowershell\sihost.exe
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\machinekeys\f686aace6942fb7f7ceb231212eef4a4_8cf7b530-613e-439b-a8c5-ccfc0e745400
- DNS ASK dn#.google
- 'dn#.google':443
- '10#.21.32.1':443
- '10#.21.64.1':443
- '%ProgramFiles(x86)%\windowspowershell\sihost.exe'