Technical Information
- <SYSTEM32>\tasks\winurl
- %PROGRAMDATA%\{dba1428e-2186-a841-5634-60ae96f0b9eb}\hostdl.exe
- %PROGRAMDATA%\microsoft\windows\start menu\programs\startup\winurl.url
- %PROGRAMDATA%\{dba1428e-2186-a841-5634-60ae96f0b9eb}\hostdl.exe
- '%WINDIR%\syswow64\schtasks.exe' /create /tn WinUrl /tr %PROGRAMDATA%\{dba1428e-2186-a841-5634-60ae96f0b9eb}\hostdl.exe /sc minute /F' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn WinUrl /tr %PROGRAMDATA%\{dba1428e-2186-a841-5634-60ae96f0b9eb}\hostdl.exe /sc minute /F
- '<SYSTEM32>\taskeng.exe' {99CE9877-6DAF-4AF7-A8CB-EE01CCD80E20} S-1-5-21-1960123792-2022915161-3775307078-1001:rgbchacvghg\user:Interactive:[1]