Technical Information
- <SYSTEM32>\tasks\protecsys
- %APPDATA%\systemserviceprovider\serviceclient.exe
- %APPDATA%\presstrak\01-29-2020
- %APPDATA%\systemserviceprovider\serviceclient.exe
- 'jf####gaeg.ddns.net':5811
- 'se#######ovider.ddnsking.com':5811
- 'se######hinker.myddns.me':5811
- 'localhost':5811
- http://ip##pi.com/json/
- DNS ASK ip##pi.com
- DNS ASK jf####gaeg.ddns.net
- DNS ASK se#######ovider.ddnsking.com
- DNS ASK se######hinker.myddns.me
- '%APPDATA%\systemserviceprovider\serviceclient.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "ProtecSys" /sc ONLOGON /tr "<Full path to file>" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "ProtecSys" /sc ONLOGON /tr "%APPDATA%\SystemServiceProvider\ServiceClient.exe" /rl HIGHEST /f