Technical Information
- '<SYSTEM32>\taskkill.exe' /PID 3076 /F
- hezhq.exe process, win32u.dll module
- hezhq.exe process, ntdll.dll module
- %TEMP%\content\3076-5376-<File name>.exe-20-25-44-453.dump
- 'de###licker.cc':443
- 'de###licker.cc':443
- DNS ASK de###licker.cc
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /C timeout /T 5 /NOBREAK & taskkill /PID 3076 /F & timeout /T 1 /NOBREAK & del "<Full path to file>"
- '<SYSTEM32>\timeout.exe' /T 5 /NOBREAK
- '<SYSTEM32>\timeout.exe' /T 1 /NOBREAK
- '<SYSTEM32>\cmd.exe' /C timeout /T 5 /NOBREAK & taskkill /PID 3076 /F & timeout /T 1 /NOBREAK & del "<Full path to file>"' (with hidden window)