Техническая информация
- '%TEMP%\afolder\PortQry.exe' /pid=3928
- '%TEMP%\afolder\PortQry.exe' /pid=3004
- '%TEMP%\afolder\PortQry.exe' -q -n localhost -e 11000
- '<SYSTEM32>\attrib.exe' -q -n localhost -e 11000
- '<SYSTEM32>\attrib.exe' +h %TEMP%\ztmp
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\attrib.exe
- %TEMP%\ztmp\tmp8662.exe
- %TEMP%\afolder\JDtrm.RDP
- %TEMP%\afolder\PortQry.exe
- %TEMP%\ztmp\tmp8610.bat
- 'localhost':11000