Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\windowssecurityhealth.exe
- '15#.#43.22.11':443
- '<DNS_SERVER>':53
- '<SYSTEM32>\schtasks.exe' /create /tn "GoogleUpdateTaskMachine" /tr "\"<Full path to file>\"" /sc onlogon /rl highest /f >nul 2>&1
- '<SYSTEM32>\schtasks.exe' /create /tn "GoogleUpdateTaskMachine" /tr "\"<Full path to file>\"" /sc onlogon /rl highest /f >nul 2>&1' (with hidden window)