Technical Information
- <SYSTEM32>\tasks\peercreator
 
- %APPDATA%\wsystempeers\wpeerc.exe
 - nul
 - %APPDATA%\wsystempeers\rcxbe7e.tmp
 
- from %APPDATA%\wsystempeers\rcxbe7e.tmp to %APPDATA%\wsystempeers\wpeerc.exe
 
- '<LOCALNET>.3.101':1443
 
- DNS ASK ap#.#pify.org
 
- '%APPDATA%\wsystempeers\wpeerc.exe'
 
- '<SYSTEM32>\cmd.exe' /c schtasks /Create /TN "PeerCreator" /TR "%APPDATA%\WSystemPeers\WPeerC.exe" /SC ONLOGON /RL HIGHEST /F >nul 2>nul
 - '<SYSTEM32>\schtasks.exe' /Create /TN "PeerCreator" /TR "%APPDATA%\WSystemPeers\WPeerC.exe" /SC ONLOGON /RL HIGHEST /F