Техническая информация
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\schtasks.exe' /create /sc onlogon /tn Origin /rl highest /ru System /tr "%APPDATA%\Origin\update.vbe"
- '<SYSTEM32>\cscript.exe' "../temp023423.vbe" //Nologo
- %APPDATA%\Origin\update.vbe
- C:\temp023423.vbe
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- C:\temp023423.vbe
- 'cr####xplorer.us':80
- 'localhost':1038
- cr####xplorer.us/api/bitcoin/balance/15qzMETkyATFsNZARqVky6eGnAnAzZSTPR
- DNS ASK cr####xplorer.us
- DNS ASK google.com