Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Realtek HD Audio Universal Service' = '%APPDATA%\Microsoft\Protect\SecurityHealthSystray.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Realtek HD Audio Watcher Service' = '%APPDATA%\Microsoft\Protect\SecurityHealthWatcher.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath <Full path to file>
- %APPDATA%\microsoft\protect\securityhealthsystray.exe
- %APPDATA%\microsoft\protect\securityhealthwatcher.exe
- %TEMP%\commonfiles-temp\user\memorandum.doc
- nul
- <Full path to file>
- %APPDATA%\microsoft\protect\securityhealthsystray.exe
- %APPDATA%\microsoft\protect\securityhealthwatcher.exe
- 'ap#.#pify.org':443
- 'on####ud.pages.dev':443
- 'ip##pi.com':80
- http://ip##pi.com/line/?fi############
- 'ap#.#pify.org':443
- 'on####ud.pages.dev':443
- DNS ASK ap#.#pify.org
- DNS ASK on####ud.pages.dev
- DNS ASK ip##pi.com
- '%APPDATA%\microsoft\protect\securityhealthsystray.exe'
- '%APPDATA%\microsoft\protect\securityhealthwatcher.exe'
- '<SYSTEM32>\attrib.exe' +h +s <Full path to file>
- '<SYSTEM32>\wbem\wmic.exe' csproduct get UUID
- '<SYSTEM32>\wbem\wmic.exe' os get Caption
- '<SYSTEM32>\wbem\wmic.exe' cpu get Name
- '<SYSTEM32>\wbem\wmic.exe' path win32_VideoController get name
- '<SYSTEM32>\netsh.exe' wlan show profiles
- '<SYSTEM32>\attrib.exe' +h +s %APPDATA%\Microsoft\Protect\SecurityHealthSystray.exe
- '<SYSTEM32>\attrib.exe' +h +s %APPDATA%\Microsoft\Protect\SecurityHealthWatcher.exe
- '<SYSTEM32>\attrib.exe' +h +s <Full path to file>' (with hidden window)
- '<SYSTEM32>\wbem\wmic.exe' csproduct get UUID' (with hidden window)
- '<SYSTEM32>\wbem\wmic.exe' os get Caption' (with hidden window)
- '<SYSTEM32>\wbem\wmic.exe' cpu get Name' (with hidden window)
- '<SYSTEM32>\wbem\wmic.exe' path win32_VideoController get name' (with hidden window)
- '<SYSTEM32>\netsh.exe' wlan show profiles' (with hidden window)
- '<SYSTEM32>\attrib.exe' +h +s %APPDATA%\Microsoft\Protect\SecurityHealthSystray.exe' (with hidden window)
- '<SYSTEM32>\attrib.exe' +h +s %APPDATA%\Microsoft\Protect\SecurityHealthWatcher.exe' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath <Full path to file>' (with hidden window)