Technical Information
- <SYSTEM32>\tasks\'winrar'
- %TEMP%\winrar-x64-591esp.exe
- %TEMP%\winrar-x64-591es.exe
- %TEMP%\winrar.exe
- %TEMP%\tmp9359.tmp.bat
- nul
- '20#.#7.156.108':9700
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\winrar-x64-591esp.exe'
- '%TEMP%\winrar-x64-591es.exe'
- '%TEMP%\winrar.exe'
- '<SYSTEM32>\schtasks.exe' /create /f /sc ONLOGON /RL HIGHEST /tn "'WinRAR"' /tr "'%TEMP%\WinRAR.exe"'' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /f /sc ONLOGON /RL HIGHEST /tn "'WinRAR"' /tr "'%TEMP%\WinRAR.exe"'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp9359.tmp.bat""
- '<SYSTEM32>\timeout.exe' 3