Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'datathef' = 'c:\Datathef\datathef.exe'
- 'C:\datathef\Rar.exe' e datathef8.rar
- 'C:\datathef\Rar.exe' e datathef7.rar
- 'C:\datathef\Rar.exe' e datathef6.rar
- 'C:\datathef\Rar.exe' /pid=1480
- 'C:\datathef\Rar.exe' e datathef10.rar
- 'C:\datathef\Rar.exe' e datathef9.rar
- 'C:\datathef\Rar.exe' e datathef2.rar
- 'C:\datathef\Rar.exe' e datathef1.rar
- 'C:\datathef\Datathef.exe'
- 'C:\datathef\Rar.exe' e datathef5.rar
- 'C:\datathef\Rar.exe' e datathef4.rar
- 'C:\datathef\Rar.exe' e datathef3.rar
- '<SYSTEM32>\reg.exe' /pid=2752
- '<SYSTEM32>\ping.exe' 120.0.0.1 -n 0 -w 1000
- '<SYSTEM32>\ftp.exe' 120.0.0.1 -n 3 -w 1000
- '<SYSTEM32>\ping.exe' /pid=3288
- '<SYSTEM32>\ping.exe' 120.0.0.1 -n 3 -w 1000
- '<SYSTEM32>\attrib.exe' +s +h +a C:\datathef
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\Datathef.Bat" "
- '<SYSTEM32>\ftp.exe' -v -i -s:C:\datathef\log
- '<SYSTEM32>\reg.exe' add hkey_local_machine\software\microsoft\windows\currentversion\run /v datathef /t reg_sz /d c:\Datathef\datathef.exe /f
- <SYSTEM32>\ftp.exe
- <SYSTEM32>\ping.exe
- %TEMP%\1.tmp\Datathef.Bat
- C:\datathef\log
- C:\datathef\Rar.exe
- C:\datathef\Datathef.exe
- 'localhost':1042
- 'localhost':1044
- 'localhost':1040
- 'localhost':1037
- 'da####ef.no-ip.info':21
- DNS ASK Da####ef.no-ip.info
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'