Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'OQDTAU' = '"%APPDATA%\Windata\Microsoft Windows Search Indexer.exe"'
- %APPDATA%\windata\microsoft windows search indexer.exe
- 'Ah#####483.portmap.io':24483
- DNS ASK Ah#####483.portmap.io
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /tn OQDTAU.exe /tr %APPDATA%\Windata\Microsoft Windows Search Indexer.exe /sc minute /mo 1' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /tn OQDTAU.exe /tr %APPDATA%\Windata\Microsoft Windows Search Indexer.exe /sc minute /mo 1
- '%WINDIR%\syswow64\schtasks.exe' /create /tn OQDTAU.exe /tr %APPDATA%\Windata\Microsoft Windows Search Indexer.exe /sc minute /mo 1