Technical Information
- <SYSTEM32>\tasks\intelprocessor
- <SYSTEM32>\tasks\puijilece
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\Microsoft\IntelUpdate.exe'"
- 'cd#.##scordapp.com':443
- 'cd#.##scordapp.com':443
- DNS ASK cd#.##scordapp.com
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\Microsoft\IntelUpdate.exe'"
- '<SYSTEM32>\cmd.exe' /c schtasks /create /tn "IntelProcessor" /tr "%LOCALAPPDATA%\Microsoft\IntelUpdate.exe" /sc onlogon /rl highest /f
- '<SYSTEM32>\schtasks.exe' /create /tn "IntelProcessor" /tr "%LOCALAPPDATA%\Microsoft\IntelUpdate.exe" /sc onlogon /rl highest /f
- '<SYSTEM32>\cmd.exe' /c schtasks /create /tn "Puijilece" /tr "%LOCALAPPDATA%\Microsoft\IntelUpdate.exe" /sc hourly /mo 1 /rl highest /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Puijilece" /tr "%LOCALAPPDATA%\Microsoft\IntelUpdate.exe" /sc hourly /mo 1 /rl highest /f