Technical Information
- <SYSTEM32>\tasks\orcus respawner
- %APPDATA%\orcuswatchdog.exe
- %APPDATA%\orcuswatchdog.exe.config
- '54.##.124.55':4782
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com
- '%APPDATA%\orcuswatchdog.exe' /launchSelfAndExit "<Full path to file>" 1180
- '%APPDATA%\orcuswatchdog.exe' /watchProcess "<Full path to file>" 1180
- '<Full path to file>' ' (with hidden window)
- '<SYSTEM32>\taskeng.exe' {98323AED-C563-4B1B-9C03-F19565B253CB} S-1-5-21-1960123792-2022915161-3775307078-1001:atszkbbam\user:Interactive:[1]