Technical Information
- %WINDIR%\tasks\nhsolh.job
- <SYSTEM32>\tasks\nhsolh
- %ALLUSERSPROFILE%\sbipwfm\nhsolh.exe
- 'ad###175x.xyz':4044
- 'se###278x.xyz':4044
- DNS ASK ad###175x.xyz
- DNS ASK se###278x.xyz
- '%ALLUSERSPROFILE%\sbipwfm\nhsolh.exe' start
- '%ALLUSERSPROFILE%\sbipwfm\nhsolh.exe' start' (with hidden window)