Technical Information
- <SYSTEM32>\tasks\runtimebroker.exe
- 'we######-40573.portmap.host':40573
- DNS ASK we######-40573.portmap.host
- '<SYSTEM32>\cmd.exe' /C SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "RuntimeBroker.exe" /tr "<Full path to file>" & exit
- '<SYSTEM32>\schtasks.exe' /CrEAte /F /sc OnLoGoN /rl HighEst /tn "RuntimeBroker.exe" /tr "<Full path to file>"