Technical Information
- <SYSTEM32>\tasks\windows-update
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.exe
- 'ho##.#60-update.com':21001
- DNS ASK ho##.#60-update.com
- '<SYSTEM32>\schtasks.exe' /create /tn windows-update /tr <Full path to file> /sc ONLOGON /ru SYSTEM
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "copy <Full path to file> ('C:\Users\'+(whoami).split('\')[1]+'\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\')"
- '<SYSTEM32>\whoami.exe'