Technical Information
- <SYSTEM32>\tasks\peercreator
- %APPDATA%\wsystempeers\wpeerc.exe
- nul
- %APPDATA%\wsystempeers\rcx42d.tmp
- from %APPDATA%\wsystempeers\rcx42d.tmp to %APPDATA%\wsystempeers\wpeerc.exe
- '<LOCALNET>.3.101':1443
- DNS ASK ap#.#pify.org
- '%APPDATA%\wsystempeers\wpeerc.exe'
- '<SYSTEM32>\cmd.exe' /c schtasks /Create /TN "PeerCreator" /TR "%APPDATA%\WSystemPeers\WPeerC.exe" /SC ONLOGON /RL HIGHEST /F >nul 2>nul
- '<SYSTEM32>\schtasks.exe' /Create /TN "PeerCreator" /TR "%APPDATA%\WSystemPeers\WPeerC.exe" /SC ONLOGON /RL HIGHEST /F