Technical Information
- <SYSTEM32>\tasks\msnet7efed7
- %APPDATA%\fa173f720000cfc5\1
- %APPDATA%\fa173f720000cfc5\time
- %APPDATA%\fa173f720000cfc5\group
- %APPDATA%\fa173f720000cfc5\hwid
- %APPDATA%\fa173f720000cfc5\settingtime
- %APPDATA%\fa173f720000cfc5\plug\1\71c59d76456946dad91eb2f4b780541f
- %APPDATA%\fa173f720000cfc5\version
- 'aw##.#xkj999.vip':80
- 'aw##.#xkj999.vip':80
- DNS ASK aw##.#xkj999.vip
- '<SYSTEM32>\cmd.exe' /c schtasks /create /tn "MsNet7EFED7" /tr "\"<Full path to file>\"" /sc onlogon /rl highest /f >nul 2>&1
- '<SYSTEM32>\schtasks.exe' /create /tn "MsNet7EFED7" /tr "\"<Full path to file>\"" /sc onlogon /rl highest /f
- '<SYSTEM32>\cmd.exe' /c schtasks /create /tn "MsNet7EFED7" /tr "\"<Full path to file>\"" /sc onlogon /rl highest /f >nul 2>&1' (with hidden window)
- '<Full path to file>' daemon 1536' (with hidden window)