date
28 May 2020 Thursday. 07:18:22 UTC
scammer/abuser
WINLOGIN.EXE
description
Possibly issued by WINLOGIN.EXE, keeps constantly changing clipboard text with this address (1LUTCmPHjHyTa5RiVTqcZ3cvkR8Qwoqzaq). Detected by MalwareBytes, after removal the issue stopped occurring.