Technical Information
- [HKLM\System\CurrentControlSet\Services\defkill] 'ImagePath' = '%TEMP%\def_kill.sys'
- 'defkill' %TEMP%\\def_kill.sys
- 'defkill' %TEMP%\def_kill.sys
- %HOMEPATH%\desktop\defender_poc_v5_log.txt
- %TEMP%\def_kill.sys
- %TEMP%\def_kill.sys
- '<SYSTEM32>\cmd.exe' /c sc create defkill type= kernel start= demand binPath= "%TEMP%\\def_kill.sys"
- '<SYSTEM32>\sc.exe' create defkill type= kernel start= demand binPath= "%TEMP%\\def_kill.sys"
- '<SYSTEM32>\cmd.exe' /c sc start defkill
- '<SYSTEM32>\sc.exe' start defkill
- '<SYSTEM32>\cmd.exe' /c sc delete defkill
- '<SYSTEM32>\sc.exe' delete defkill