Техническая информация
- '<SYSTEM32>\cmd.exe' /S /Ktasklist > %USERPROFILE%\Desktop\tasklist.txt
- '<SYSTEM32>\cmd.exe' /S /K<SYSTEM32>\notepad.exe %USERPROFILE%\Desktop\tasklist.txt
- '<SYSTEM32>\cmd.exe' /S /K%USERPROFILE%\AppData\Local\Temp\shell.exe /S /K telnet 8.8.8.8 53
- '<SYSTEM32>\cmd.exe' /S /Kcopy <SYSTEM32>\cmd.exe %USERPROFILE%\AppData\Local\Temp\shell.exe
- '%ProgramFiles%\internet explorer\iexplore.exe' https://www.ca###nblack.com/
- DNS ASK ca###nblack.com
- ClassName: '' WindowName: ''
- ClassName: 'MsoHelp11' WindowName: ''
- ClassName: 'AgentAnim' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<SYSTEM32>\notepad.exe' %HOMEPATH%\Desktop\tasklist.txt
- '<SYSTEM32>\tasklist.exe' and Settings\user\Desktop\tasklist.txt
- '<SYSTEM32>\rundll32.exe' "%ProgramFiles%\Microsoft Office\Office12\GrooveUtil.DLL",GetResourceModulePath hsUJ/Q+IsMCiNGk552Id8PAFuDsgYWHp