Technical Information
- <SYSTEM32>\tasks\monitor
- D:\civilink\monitor\monitor.bat
- D:\civilink\monitor\duanxin.ini
- D:\civilink\monitor\duanxin.bat
- D:\civilink\monitor\wget.exe.1
- D:\civilink\monitor\mailsend.exe.1
- D:\civilink\monitor\md5.exe.1
- D:\civilink\monitor\temp.ini
- D:\civilink\monitor\monitor.ini
- D:\civilink\monitor\wget.exe
- D:\civilink\monitor\md5.exe
- D:\civilink\monitor\mailsend.exe
- DNS ASK be#####xtne.hichina.com
- ClassName: 'EDIT' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c "D:\civilink\Monitor\Monitor.bat"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""D:\civilink\Monitor\Monitor.bat" -i"
- '%WINDIR%\syswow64\schtasks.exe' /create /ru system /tn Monitor /sc MINUTE /MO 5 /st 00:01 /tr "D:\civilink\Monitor\Monitor.bat" /f
- '<SYSTEM32>\cmd.exe' /c "D:\civilink\Monitor\Monitor.bat"
- '<SYSTEM32>\cmd.exe' /c ping -n 1 -w 0 -l 0 befjllextne.hichina.com|findstr /c:"["
- '<SYSTEM32>\ping.exe' -n 1 -w 0 -l 0 befjllextne.hichina.com
- '<SYSTEM32>\findstr.exe' /c:"["