Technical Information
- <SYSTEM32>\cmd.exe
- '17#.20.10.4':8000
- '10.#.103.61':8000
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\cmd.exe' /C systeminfo
- '<SYSTEM32>\systeminfo.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -Command "Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntiVirusProduct | Select-Object -ExpandProperty displayName"
- '<SYSTEM32>\eventcreate.exe' /ID 100 /L APPLICATION /T INFORMATION /D "System Maintenance Check Completed. No issues found."
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -Command "$_31863226='$msg = \"Hello from Polymorphic!\" Write-Host $msg Write-Host (\"Time: \" + (Get-Date))'; iex $_31863226 "