Technical Information
- <SYSTEM32>\tasks\firefox default browser agent 5f723f34f7c6fbbf
- %APPDATA%\rfjtwrw
- %APPDATA%\rfjtwrw
- 'ho####ost-file8.com':80
- http://ho####ost-file8.com/
- DNS ASK ho####ile-host6.com
- DNS ASK ho####ost-file8.com
- '%APPDATA%\rfjtwrw'
- '%APPDATA%\rfjtwrw' ' (with hidden window)
- '<SYSTEM32>\taskeng.exe' {D303C0F4-49AB-4FF9-A7A3-4398750DB591} S-1-5-21-1238866942-1249195528-555854008-1000:mfmyyqehdmia\user:Interactive:[1]