PiaoYes v2

Copyright © MegaSecurity

By ?


Informations
From China
Author ?
Family PiaoYes
Category Remote Access
Version PiaoYes v2
Language Delphi
Additional Information
Client.exe:
dropped file:
c:\WINDOWS\SYSTEM\client.exe 

size: 171.008 bytes 

port: 2485, 8888, 21009 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "piaoyes" 

registry added:
HKEY_LOCAL_MACHINE\Software\piaoyes 

Tries to connect to specified IRC server and joins a channel to listen for commands

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.