Technical Information
- <SYSTEM32>\tasks\peercreator
- %APPDATA%\wsystempeers\wpeerc.exe
- nul
- %APPDATA%\wsystempeers\rcxa2c8.tmp
- from %APPDATA%\wsystempeers\rcxa2c8.tmp to %APPDATA%\wsystempeers\wpeerc.exe
- 'ap#.#pify.org':80
- '<LOCALNET>.3.101':1443
- http://ap#.#pify.org/
- DNS ASK ap#.#pify.org
- '%APPDATA%\wsystempeers\wpeerc.exe'
- '<SYSTEM32>\cmd.exe' /c schtasks /Create /TN "PeerCreator" /TR "%APPDATA%\WSystemPeers\WPeerC.exe" /SC ONLOGON /RL HIGHEST /F >nul 2>nul
- '<SYSTEM32>\schtasks.exe' /Create /TN "PeerCreator" /TR "%APPDATA%\WSystemPeers\WPeerC.exe" /SC ONLOGON /RL HIGHEST /F