Technical Information
- '%TEMP%\vcredist_x86.exe'
- '%TEMP%\vcredist_x86.exe' (downloaded from the Internet)
- '<SYSTEM32>\schtasks.exe' /Create /TN "OXDMRF\OXDMRF" /XML "%APPDATA%\OXDMRF\a00000.xml"
- %APPDATA%\Imminent\Monitoring\network.dat
- %APPDATA%\Imminent\Monitoring\system.dat
- %TEMP%\vcredist_x86.exe
- %APPDATA%\OXDMRF\OXDMRF.exe
- %APPDATA%\OXDMRF\a00000.xml
- %APPDATA%\Imminent\Logs\22-11-2017
- %APPDATA%\OXDMRF\a00000.xml
- '20#.#6.232.182':80
- 'wp#d':80
- '18#.#9.10.30':443
- http://download.microsoft.com/download/1/1/1/1116b75a-9ec3-481a-a3c8-1777b5381140/vcredist_x86.exe via 20#.#6.232.182
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK download.microsoft.com
- DNS ASK wp#d