Technical Information
- <SYSTEM32>\tasks\task5h3dku8
- C:\users\public\winlogon.exe
- C:\users\public\g4h5j2.bat
- C:\users\public\stsk.exe
- C:\users\public\studio.exe
- C:\users\public\stsk.exe
- http://19#.#27.215.143/wg9KgT
- DNS ASK google.com
- 'C:\users\public\winlogon.exe'
- 'C:\users\public\stsk.exe' /create /tn "Task5H3DKU8" /tr C:\Users\Public\winlogon.exe /sc onlogon
- '<SYSTEM32>\cmd.exe' /c C:\Users\Public\g4h5j2.bat
- '<SYSTEM32>\cmd.exe' /C choice /C Y /N /D Y /T 5 & Del "<Full path to file>" & Del C:\Users\Public\tmpdir\tmpd.bat & Del C:\Users\Public\tmpdir\tmps.bat & Del C:\Users\Public\tmp.bat & Del C:\Users\Public\g4h5j2.ba...
- '<SYSTEM32>\choice.exe' /C Y /N /D Y /T 5