Technical Information
- <SYSTEM32>\tasks\updates\jhnuxlwowcr
- %APPDATA%\jhnuxlwowcr.exe
- %TEMP%\tmp7f4c.tmp
- %TEMP%\tmp7f4c.tmp
- '93.##5.20.247':9788
- 'ap#.ip.sb':443
- http://93.###.20.247:9788/ via 93.##5.20.247
- DNS ASK ap#.ip.sb
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\jhNUxlwowcr" /XML "%TEMP%\tmp7F4C.tmp"' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\jhNUxlwowcr" /XML "%TEMP%\tmp7F4C.tmp"