Technical Information
- <SYSTEM32>\tasks\ke7oqkjtbr9g
- %ALLUSERSPROFILE%\gcwfglmbhnng.exe
- '14#.#1.90.29':56001
- '14#.#1.90.29':56002
- '14#.#1.90.29':56003
- '<DNS_SERVER>':53
- '15#.#01.1.91':443
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /Create /TN "ke7OQKjTbr9G" /TR "%ALLUSERSPROFILE%\GcWFglmBhnNG.exe" /SC ONLOGON /RL HIGHEST /F
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "ke7OQKjTbr9G" /TR "%ALLUSERSPROFILE%\GcWFglmBhnNG.exe" /SC ONLOGON /RL HIGHEST /F