Technical Information
- <SYSTEM32>\tasks\firefox default browser agent 1e4907a5fcee5e23
- %WINDIR%\explorer.exe
- %APPDATA%\ttuutug
- %APPDATA%\ttuutug
- 'ho####ile-host6.com':80
- http://ho####ile-host6.com/
- DNS ASK ho####ile-host6.com
- '%APPDATA%\ttuutug'
- '%APPDATA%\ttuutug' ' (with hidden window)
- '<SYSTEM32>\taskeng.exe' {07DA411A-86FC-42C3-A784-C9B0F958710B} S-1-5-21-1238866942-1249195528-555854008-1000:irndkrcasja\user:Interactive:[1]