Technical Information
- <SYSTEM32>\tasks\ithealthmonitor
- %ProgramFiles%\ithealthmonitor\<File name>.exe
- nul
- 'bu####alassad.store':443
- 'bu####alassad.store':443
- DNS ASK bu####alassad.store
- DNS ASK yo######lback-domain.com
- '%ProgramFiles%\ithealthmonitor\<File name>.exe'
- '<SYSTEM32>\schtasks.exe' /Delete /TN ITHealthMonitor /F
- '<SYSTEM32>\schtasks.exe' /Create /SC MINUTE /MO 2 /TN ITHealthMonitor /TR "\"%ProgramFiles%\ITHealthMonitor\<File name>.exe\"" /F /RL HIGHEST
- '<SYSTEM32>\schtasks.exe' /Delete /TN ITHealthMonitor /F' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /Create /SC MINUTE /MO 2 /TN ITHealthMonitor /TR "\"%ProgramFiles%\ITHealthMonitor\<File name>.exe\"" /F /RL HIGHEST' (with hidden window)