Technical Information
- <SYSTEM32>\tasks\peercreator
 
- %APPDATA%\wsystempeers\wpeerc.exe
 - nul
 - %APPDATA%\wsystempeers\rcx6f5f.tmp
 
- from %APPDATA%\wsystempeers\rcx6f5f.tmp to %APPDATA%\wsystempeers\wpeerc.exe
 
- 'ap#.#pify.org':80
 - '<LOCALNET>.3.101':1443
 
- http://ap#.#pify.org/
 
- DNS ASK ap#.#pify.org
 
- '%APPDATA%\wsystempeers\wpeerc.exe'
 
- '<SYSTEM32>\cmd.exe' /c schtasks /Create /TN "PeerCreator" /TR "%APPDATA%\WSystemPeers\WPeerC.exe" /SC ONLOGON /RL HIGHEST /F >nul 2>nul
 - '<SYSTEM32>\schtasks.exe' /Create /TN "PeerCreator" /TR "%APPDATA%\WSystemPeers\WPeerC.exe" /SC ONLOGON /RL HIGHEST /F