Technical Information
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name=\"ctfmon\" dir=in action=allow program=\"<Full path to file>\" enable=yes
- '<SYSTEM32>\cmd.exe' /Q /C reg add "HKCU\Software\Client-Server Runtime Subsystem" /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Client-Server Runtime Subsystem" /f
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall add rule name=\"ctfmon\" dir=in action=allow program=\"<Full path to file>\" enable=yes"
- '<SYSTEM32>\cmd.exe' /Q /C move /Y <Full path to file> %WINDIR%\ctfmon.exe
- '<SYSTEM32>\cmd.exe' /C "SCHTASKS /CREATE /SC ONLOGON /RL HIGHEST /TR %WINDIR%\ctfmon.exe /TN HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ctfmon /F"
- '<SYSTEM32>\schtasks.exe' /CREATE /SC ONLOGON /RL HIGHEST /TR %WINDIR%\ctfmon.exe /TN HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ctfmon /F
- %APPDATA%\ServiceHelper.exe
- from <Full path to file> to %WINDIR%\ctfmon.exe
- 'ch#####.amazonaws.com':80
- http://ch#####.amazonaws.com/
- DNS ASK ch#####.amazonaws.com