Technical Information
- <SYSTEM32>\tasks\startmonitor
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'DoNotAllowExceptions' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- <SYSTEM32>\winver.exe
- <SYSTEM32>\computerdefaults.exe
- <SYSTEM32>\securityhealthservice.exe
- <SYSTEM32>\securityhealthsystray.exe
- %ALLUSERSPROFILE%\golden\run_55045585.exe
- %TEMP%\~dump.tmp
- %ALLUSERSPROFILE%\microsoft\windows security health\logs\shs-01192026-182621-7-7f-19041.1.amd64fre.vb_release.191206-1406.etl
- '<DNS_SERVER>':53
- '10#.#01.176.131':21501
- DNS ASK google.com
- '%ALLUSERSPROFILE%\golden\run_55045585.exe' -bypass
- '%WINDIR%\explorer.exe' shell:::{1D158548-6368-492D-94DF-DD928B398CBD}
- '<SYSTEM32>\winver.exe'
- '<SYSTEM32>\cmd.exe' /c "gpupdate /force"
- '<SYSTEM32>\gpupdate.exe' /force
- '<SYSTEM32>\securityhealthservice.exe'
- '%WINDIR%\explorer.exe' shell:::{1D158548-6368-492D-94DF-DD928B398CBD}' (with hidden window)
- '%ALLUSERSPROFILE%\golden\run_55045585.exe' -bypass' (with hidden window)
- '<SYSTEM32>\winver.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "gpupdate /force"' (with hidden window)