Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\hxd\hxd.exe
- '%TEMP%\leads.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\vbc.exe
- %TEMP%\leads.exe
- http://23.##4.227.237/inject/Leads.exe
- '%WINDIR%\microsoft.net\framework\v4.0.30319\vbc.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath '"%APPDATA%\Microsoft\Windows\Start Menu\Programs\HxD\HxD.exe"'