Technical Information
- <SYSTEM32>\tasks\svhost
- %TEMP%\lol.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>sgotixybmulfqmmvenrc.dll
- %APPDATA%\svhost\svhost.exe
- %TEMP%\lol.exe
- %APPDATA%\svhost\svhost.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>sgotixybmulfqmmvenrc.dll
- '15#.#77.61.79':4782
- 'ra#.####ubusercontent.com':443
- 'he######dictcheat.imfast.io':443
- DNS ASK ra#.####ubusercontent.com
- DNS ASK he######dictcheat.imfast.io
- '%TEMP%\lol.exe'
- '%APPDATA%\svhost\svhost.exe'
- '%TEMP%\lol.exe' ' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /tn "svhost" /sc ONLOGON /tr "%TEMP%\lol.exe" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "svhost" /sc ONLOGON /tr "%APPDATA%\svhost\svhost.exe" /rl HIGHEST /f