Техническая информация
- '%HOMEPATH%\conhost.exe'
- '<SYSTEM32>\cmd.exe' /k %HOMEPATH%\conhost.exe
- %HOMEPATH%\conhost.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\conhost.exe
- 'cl#####ecurity.ggpht.ml':443
- DNS ASK cl#####ecurity.ggpht.ml
- '<SYSTEM32>\cmd.exe' /k %HOMEPATH%\conhost.exe' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKCU\Console\%SystemRoot^%_system32_cmd.exe /v CodePage /t REG_DWORD /d 65001 /f
- '%WINDIR%\syswow64\reg.exe' ADD HKCU\Console\%SystemRoot%_system32_cmd.exe /v CodePage /t REG_DWORD /d 65001 /f
- '%WINDIR%\syswow64\cmd.exe' /c systeminfo
- '%WINDIR%\syswow64\systeminfo.exe'
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD \"HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\" /t REG_SZ /F /D \"%userprofile%\conhost.exe\"
- '%WINDIR%\syswow64\reg.exe' ADD \"HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\" /t REG_SZ /F /D \"%HOMEPATH%\conhost.exe\"
- '%WINDIR%\syswow64\cmd.exe' /c attrib +h +s %userprofile%\conhost.exe
- '%WINDIR%\syswow64\attrib.exe' +h +s %HOMEPATH%\conhost.exe