Technical Information
- <SYSTEM32>\tasks\windows update f118abd8
- <SYSTEM32>\tasks\windows update 9059a83e
- <SYSTEM32>\tasks\windows update 11bcc632
- <SYSTEM32>\tasks\windows update 3d115f8c
- <SYSTEM32>\tasks\windows update 1dd523b7
- %TEMP%\7495.tmp
- %PROGRAMDATA%\winlogon\winlogon.lnk
- %PROGRAMDATA%\winlogon\d08590a23476
- %TEMP%\7495.tmp
- %PROGRAMDATA%\winlogon\d08590a23476
- '50.##6.23.211':53
- '19#.#83.98.154':53
- '13#.#55.73.90':53
- 'dn#.#ot-bit.org':53
- DNS ASK dn#.#ot-bit.org
- ClassName: 'cf9a8fbd2b69' WindowName: 'c89d88ba2c6e0'
- '<SYSTEM32>\rundll32.exe' "%PROGRAMDATA%\Winlogon\winlogon.lnk",DllGetClassObject host