Technical Information
- <SYSTEM32>\tasks\taskhostw
- <SYSTEM32>\tasks\fontdrvhost
- <SYSTEM32>\tasks\dwm
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoLogo -NoProfile -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass -EncodedCommand IwAgABgEQQQ6BDsETgRHBDUEPQQ4BE8EIABEAGUAZgBlAG4AZABlAHIAOgAgAFIAbwBhAG0AaQBuAGcALAAgAEwAbwBjAGEAbA...
- %LOCALAPPDATA%\opera software\taskhostw.exe
- %ProgramFiles(x86)%\internet explorer\fontdrvhost.exe
- %LOCALAPPDATA%\connecteddevicesplatform\dwm.exe
- DNS ASK dn#.google
- 'dn#.google':443
- '18#.#14.97.1':443
- '18#.#14.96.1':443
- '%LOCALAPPDATA%\connecteddevicesplatform\dwm.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe'
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted -p -s UmRdpService
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoLogo -NoProfile -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass -EncodedCommand IwAgABgEQQQ6BDsETgRHBDUEPQQ4BE8EIABEAGUAZgBlAG4AZABlAHIAOgAgAFIAbwBhAG0AaQBuAGcALAAgAEwAbwBjAGEAbA...' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' ' (with hidden window)