Technical Information
- <SYSTEM32>\tasks\updateservice
- <SYSTEM32>\svchost.exe
- %TEMP%\msedge.exe
- nul
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK gi##ub.com
- DNS ASK ra#.####ubusercontent.com
- '%TEMP%\msedge.exe'
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /tn UpdateService /f
- '<SYSTEM32>\schtasks.exe' /delete /tn UpdateService /f
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc ONLOGON /tn UpdateService /tr \"%TEMP%\msedge.exe\" /ru %USERNAME%
- '<SYSTEM32>\schtasks.exe' /create /f /sc ONLOGON /tn UpdateService /tr \"%TEMP%\msedge.exe\" /ru user