Technical Information
- <SYSTEM32>\tasks\windows\servicerun
- from <Full path to file> to %PROGRAMDATA%\vshub.exe
- 'se###hisweb.com':80
- DNS ASK dr##en.xyz
- DNS ASK se###hisweb.com
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\attrib.exe' +s +h "%PROGRAMDATA%\vshub.exe"' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn \Windows\ServiceRun /tr "%PROGRAMDATA%\vshub.exe" /st 00:00 /sc daily /du 9999:59 /ri 2 /f' (with hidden window)
- '%WINDIR%\syswow64\attrib.exe' +s +h "%PROGRAMDATA%\vshub.exe"
- '%WINDIR%\syswow64\schtasks.exe' /create /tn \Windows\ServiceRun /tr "%PROGRAMDATA%\vshub.exe" /st 00:00 /sc daily /du 9999:59 /ri 2 /f