Technical Information
- <SYSTEM32>\tasks\lsass
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath %APPDATA%\Mozilla\lsass.exe
- %APPDATA%\mozilla\lsass.exe
- nul
- 'ap#.##legram.org':443
- 'ap#.##legram.org':443
- DNS ASK ap#.##legram.org
- '%APPDATA%\mozilla\lsass.exe'
- '<SYSTEM32>\schtasks.exe' /Create /F /SC ONLOGON /TN lsass /TR \"%APPDATA%\Mozilla\lsass.exe\" /RL HIGHEST
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath %APPDATA%\Mozilla\lsass.exe' (with hidden window)