Technical Information
- Windows Defender
- '<SYSTEM32>\taskkill.exe' /IM <File name>.exe /F /T
- <SYSTEM32>\cmd.exe
- %APPDATA%\spf\unknown.log
- %TEMP%\rno0wqjv.bat
- %TEMP%\65c25dc3-0117-4f27-bdc9-b298b4453100.bat
- %TEMP%\65c25dc3-0117-4f27-bdc9-b298b4453100.bat
- ClassName: '' WindowName: ''
- '%TEMP%\rno0wqjv.bat' ok
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\65c25dc3-0117-4f27-bdc9-b298b4453100.bat"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "%TEMP%\65c25dc3-0117-4f27-bdc9-b298b4453100.bat"