Technical Information
- <SYSTEM32>\tasks\sihost
- <SYSTEM32>\tasks\spoolsv
- %WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe
- %APPDATA%\alnhg4hini.exe
- %APPDATA%\n6vgilxtqt.exe
- %TEMP%\test.exe
- %TEMP%\grape.exe
- %TEMP%\sihost.exe
- %LOCALAPPDATA%\mozilla\spoolsv.exe
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\machinekeys\f686aace6942fb7f7ceb231212eef4a4_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %TEMP%\sihost.exe
- %LOCALAPPDATA%\mozilla\spoolsv.exe
- DNS ASK dn#.google
- 'dn#.google':443
- '10#.21.16.1':443
- '10#.#1.112.1':443
- '%APPDATA%\alnhg4hini.exe'
- '%APPDATA%\n6vgilxtqt.exe'
- '%TEMP%\test.exe'
- '%TEMP%\grape.exe'
- '%LOCALAPPDATA%\mozilla\spoolsv.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe'
- '%WINDIR%\syswow64\reagentc.exe' /disable
- '%APPDATA%\alnhg4hini.exe' ' (with hidden window)
- '%APPDATA%\n6vgilxtqt.exe' ' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' ' (with hidden window)