Техническая информация
- 360tray.exe
- %WINDIR%\Fonts\2018714083618Update.bat
- %WINDIR%\Fonts\2018714083608.bat
- %WINDIR%\Fonts\2018714083608.bat
- 'localhost':1038
- 'do.##crbots.com':80
- http://do.##crbots.com/page/goods180402.txt
- DNS ASK do.##crbots.com
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\cmd.exe" /E /G SYSTEM:F
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\cmd.exe" /E /G Everyone:F
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\net.exe" /E /G SYSTEM:F
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\net.exe" /E /G Everyone:F
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\net1.exe" /E /G SYSTEM:F
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\net1.exe" /E /G Everyone:F
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\WMIC.exe" /E /G SYSTEM:F
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\WMIC.exe" /E /G Everyone:F
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\Fonts\2018714083618Update.bat
- '<SYSTEM32>\cmd.exe' /c "%WINDIR%\Fonts\2018714083618Update.bat"
- '<SYSTEM32>\sc.exe' stop WindowsUpdate
- '<SYSTEM32>\cmd.exe' /c "%WINDIR%\Fonts\\2018714083608.bat"