Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\PSEXESVC] 'ImagePath' = '%WINDIR%\PSEXESVC.exe'
- %WINDIR%\PSEXESVC.exe
- %TEMP%\7zS1.tmp\PsExec.exe
- %TEMP%\7zS1.tmp\nircmd.exe
- %ProgramFiles%\GTC
- %WINDIR%\Temp\GTC_Cred-install.log
- \Device\LanmanRedirector\CRNJEUFU\pipe\PSEXESVC
- %TEMP%\7zS1.tmp\gtc_cred.exe
- %TEMP%\7zS1.tmp\gtc_cred.xml
- %TEMP%\7zS1.tmp\findpid.cmd
- %TEMP%\7zS1.tmp\bootstrap.cmd
- %TEMP%\7zS1.tmp\payload.cmd
- %TEMP%\7zS1.tmp\nirscript.txt
- %TEMP%\7zS1.tmp\nirpid.txt
- %WINDIR%\PSEXESVC.exe
- '<LOCALNET>.0.2':139
- 'localhost':445
- '%WINDIR%\PSEXESVC.exe'
- '%TEMP%\7zS1.tmp\PsExec.exe' -d -s -accepteula -nobanner -w "%TEMP%\7zS1.tmp" cmd /c bootstrap.cmd
- '%TEMP%\7zS1.tmp\nircmd.exe' script nirscript.txt
- '<SYSTEM32>\attrib.exe' +r <SYSTEM32>\Tasks\gtc_cred
- '<SYSTEM32>\schtasks.exe' /Create /XML gtc_cred.xml /TN gtc_cred
- '<SYSTEM32>\schtasks.exe' /Run /TN gtc_cred
- '<SYSTEM32>\attrib.exe' +r "%ProgramFiles%\GTC\gtc_cred.exe"
- '<SYSTEM32>\schtasks.exe' /delete /f /TN pwd_set
- '<SYSTEM32>\cmd.exe' /c bootstrap.cmd
- '<SYSTEM32>\cmd.exe' /c findpid.cmd
- '<SYSTEM32>\attrib.exe' -r <SYSTEM32>\Tasks\pwd_set
- '<SYSTEM32>\attrib.exe' -h -s -r "%ProgramFiles%\GTC\gtc_cred.exe"