Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- <SYSTEM32>\net1.exe localgroup %USERNAME%s UndeadNet /add
- <SYSTEM32>\net1.exe user UndeadNet /add
- %WINDIR%\regedit.exe /s %TEMP%\HideUser.reg
- <SYSTEM32>\netsh.exe firewall set opmode mode=disable
- <SYSTEM32>\netsh.exe firewall set opmode disable
- <SYSTEM32>\attrib.exe -r -h "%TEMP%\1.tmp\Undeadnet.bat"
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\Undeadnet.bat""
- <SYSTEM32>\attrib.exe -r -h C:\Undeadnet.bat
- <SYSTEM32>\ipconfig.exe /all
- <SYSTEM32>\cscript.exe IpScan.js
- <Текущая директория>\ipconfig.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\n09230945[1].asp
- %TEMP%\HideUser.reg
- <Текущая директория>\Command.dll
- %TEMP%\1.tmp\Undeadnet.bat
- <Текущая директория>\ip.txt
- <Текущая директория>\IpScan.js
- %TEMP%\HideUser.reg
- 'www.wh###smyip.com':80
- 'localhost':1035
- www.wh###smyip.com/automation/n09230945.asp
- DNS ASK www.wh###smyip.com
- '<IP-адрес в локальной сети>':1036
- ClassName: 'RegEdit_RegEdit' WindowName: ''