Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\windowsbackup.bat
 
- %TEMP%\content\5320-5328-<File name>.exe-20-59-10-841.dump
 
- '10#.#89.20.36':6000
 
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' [Console]::Title = ((Get-ScheduledTask).Actions.Execute -join '').Contains('<PATH_SAMPLE>')
 - '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' [Console]::Title = ((Get-ScheduledTask).Actions.Execute -join '').Contains('<PATH_SAMPLE>')' (with hidden window)