Technical Information
- <SYSTEM32>\tasks\usnetworkservice
- %APPDATA%\inexplor\<File name>.exe
- <Current directory>\del.bat
- nul
- '62.##9.13.215':11000
- '%APPDATA%\inexplor\<File name>.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 1 /tn "USNetworkService" /tr %APPDATA%\InExplor\<File name>.exe
- '%WINDIR%\syswow64\cmd.exe' /c ""<Current directory>\del.bat" "
- '%WINDIR%\syswow64\timeout.exe' /t 5 /nobreak
- '<SYSTEM32>\taskeng.exe' {3208B75A-01E0-4C56-B6C6-45825F04EBFA} S-1-5-21-3691498038-2086406363-2140527554-1000:tkudsyplg\user:Interactive:[1]
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 1 /tn "USNetworkService" /tr %APPDATA%\InExplor\<File name>.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""<Current directory>\del.bat" "' (with hidden window)
- '%APPDATA%\inexplor\<File name>.exe' ' (with hidden window)