Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '18.exe' = '%APPDATA%Microsoft\System\Services\18.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '18.exe' = '%APPDATA%Microsoft\System\Services\18.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Startup RegKey Name' = '\Startup Folder Name\MyFile.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Startup RegKey Name' = '%LOCALAPPDATA%\Startup Folder Name\MyFile.exe'
- %APPDATA%microsoft\system\services\18.exe
- %TEMP%\<File name>\<File name>.exe
- nul
- C:\startup folder name\myfile.exe
- %LOCALAPPDATA%\startup folder name\myfile.exe
- %APPDATA%\imminent\logs\11-11-2020
- %APPDATA%\imminent\path.dat
- %TEMP%\<File name>\<File name>.exe
- '<LOCALNET>.0.22':4777
- '%TEMP%\<File name>\<File name>.exe'
- '%WINDIR%\syswow64\cmd.exe' /C ping 1.1.1.1 -n 1 -w 1000 > Nul & Del "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\taskmgr.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C ping 1.1.1.1 -n 1 -w 1000 > Nul & Del "<Full path to file>"
- '%WINDIR%\syswow64\ping.exe' 1.1.1.1 -n 1 -w 1000
- '%WINDIR%\syswow64\taskmgr.exe'