Technical Information
- '%WINDIR%\syswow64\taskkill.exe' -f -imchrome.exe
- %TEMP%\login data
- %TEMP%\cfdb1fba
- %TEMP%\login data
- %LOCALAPPDATA%\google\chrome\user data\local state
- 'li#######.members.linode.com':80
- DNS ASK ab########yhost.workisboring.com
- DNS ASK ab############t30C66E8C4EFE79E7.workisboring.com
- DNS ASK ab############t6692AF5D81AE88F7.workisboring.com
- DNS ASK ab############t4FE80127C573F564.workisboring.com
- DNS ASK ab############tB544E30B3EF077E6.workisboring.com
- DNS ASK ab############t678F5F84B858DE59.workisboring.com
- DNS ASK ab############t8AA15B85BC6CCA4C.workisboring.com
- DNS ASK ab############t1CD41CCD6185E356.workisboring.com
- DNS ASK ab############tA9579B45F4240277.workisboring.com
- DNS ASK ab############t2BF834D40CC3A593.workisboring.com
- DNS ASK ab############t19DA13C57294938E.workisboring.com
- DNS ASK li#######.members.linode.com
- ClassName: 'OSKMainClass' WindowName: ''
- '%WINDIR%\syswow64\taskkill.exe' -f -imchrome.exe' (with hidden window)