Technical Information
- <SYSTEM32>\tasks\firefox default browser agent 1ceed9cb69a49d7b
- %WINDIR%\explorer.exe
- gtgctjj
- %APPDATA%\gtgctjj
- %APPDATA%\gtgctjj
- DNS ASK ho####ile-host6.com
- DNS ASK ho####ost-file8.com
- '%APPDATA%\gtgctjj'
- '%APPDATA%\gtgctjj' ' (with hidden window)
- '<SYSTEM32>\taskeng.exe' {78BD57DE-289C-4ED0-9960-C669430A80CD} S-1-5-21-1960123792-2022915161-3775307078-1001:orsmcy\user:Interactive:[1]