Техническая информация
- <SYSTEM32>\tasks\peercreator
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath $env:APPDATA"
- %APPDATA%\peerservice\peerservice.exe
- %APPDATA%\peerservice\rcx76d6.tmp
- nul
- %TEMP%\chw.aof
- %APPDATA%\peerservice\rcx76d6.tmp в %APPDATA%\peerservice\peerservice.exe
- 'localhost':1443
- '%APPDATA%\peerservice\peerservice.exe'
- '<SYSTEM32>\cmd.exe' /C "schtasks /Create /TN "PeerCreator" /TR "%APPDATA%\PeerService\PeerService.exe" /SC ONLOGON /RL HIGHEST /F >nul 2>nul"
- '<SYSTEM32>\schtasks.exe' /Create /TN "PeerCreator" /TR "%APPDATA%\PeerService\PeerService.exe" /SC ONLOGON /RL HIGHEST /F
- '<SYSTEM32>\cmd.exe' /C "powershell -Command "Add-MpPreference -ExclusionPath $env:APPDATA""
- '<SYSTEM32>\cmd.exe' /C "for /l %i in () do (tasklist | find /i "PeerService.exe" >nul || (copy /y "%TEMP%\\chw.aof" "%APPDATA%\PeerService\PeerService.exe" & start "" "%APPDATA%\PeerService\PeerService.exe" & exit...
- '<SYSTEM32>\tasklist.exe'
- '<SYSTEM32>\find.exe' /i "PeerService.exe"
- '<SYSTEM32>\timeout.exe' /t 5