Technical Information
- <SYSTEM32>\tasks\maintains.exe
- %TEMP%\maintains.exe
- %TEMP%\tmpeacf.tmp.vbs
- %TEMP%\tmpeacf.tmp.vbs
- 'tu######ibov.duckdns.org':1604
- DNS ASK tu######ibov.duckdns.org
- '<SYSTEM32>\wscript.exe' "%TEMP%\tmpEACF.tmp.vbs"
- '%TEMP%\maintains.exe'
- '<SYSTEM32>\schtasks.exe' /create /sc onlogon /rl highest /tn Maintains.exe /tr "%TEMP%\Maintains.exe' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /sc onlogon /rl highest /tn Maintains.exe /tr "%TEMP%\Maintains.exe