Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SecurityHealthSystray.exe' = '%APPDATA%\Defender\SecurityHealthSystray.exe'
- <SYSTEM32>\tasks\defender
- %APPDATA%\defender\securityhealthsystray.exe
- %APPDATA%\defender\securityhealthsystray.exe
- 'ip###ger.org':443
- DNS ASK ip###ger.org
- '%APPDATA%\defender\securityhealthsystray.exe'
- '<SYSTEM32>\schtasks.exe' /create /f /sc ONLOGON /RL HIGHEST /tn Defender /tr "'%APPDATA%\Defender\SecurityHealthSystray.exe'"' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /f /sc ONLOGON /RL HIGHEST /tn Defender /tr "'%APPDATA%\Defender\SecurityHealthSystray.exe'"