Technical Information
- <SYSTEM32>\tasks\update\google update
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\chrome.exe
- %TEMP%\a11111.xml
- %TEMP%\chrome.exe
- %TEMP%\a11111.xml
- '23.##.216.247':5150
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Update\google update" /XML "%TEMP%\a11111.xml"' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Update\google update" /XML "%TEMP%\a11111.xml"
- '%WINDIR%\syswow64\svchost.exe'