Техническая информация
- '<SYSTEM32>\wscript.exe' "%TEMP%\uacinstall.vbs"
- '<SYSTEM32>\msiexec.exe' /qr /i %TEMP%\Agent_x86.msi /quiet /qn /norestart /l*v %TEMP%\ra-agent-install.log ALLUSERS=1 REBOOT=ReallySuppress P_CONNECTION_CHOSEN=Host P_HOSTNAME="era.viptsg.com" P_PORT="2222" P_CERT_PAT...
- '<SYSTEM32>\msiexec.exe' /V
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\selfdel0.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\batfile.bat" "
- '<SYSTEM32>\cmd.exe' /c ver
- '<SYSTEM32>\cmd.exe' /c echo Version 5.1.2600
- %TEMP%\1.tmp\batfile.bat
- %TEMP%\1.tmp\batfile.bat
- %TEMP%\uacinstall.vbs
- 're####tory.eset.com':80
- http://re####tory.eset.com/v1/com/eset/apps/business/era/agent/v6/6.3.136.0/Agent_x86.msi
- DNS ASK re####tory.eset.com