Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,"%LOCALAPPDATA%\Pic1fPBkmq\LOHejsSdpL.exe" -s'
- <SYSTEM32>\tasks\svchost
- %TEMP%\burs.exe
- %TEMP%\dsmaqtwlzpxl.png
- %TEMP%\zuxwcnpio7.exe
- %LOCALAPPDATA%\pic1fpbkmq\lohejssdpl.exe
- %TEMP%\plyfiunqnqj.txt
- <SYSTEM32>\subdir\client.exe
- %LOCALAPPDATA%\pic1fpbkmq\lohejssdpl.exe
- 'ma######bi31.duckdns.org':4782
- DNS ASK ma######bi31.duckdns.org
- '%TEMP%\burs.exe'
- '%TEMP%\zuxwcnpio7.exe'
- '<SYSTEM32>\subdir\client.exe'
- '%WINDIR%\syswow64\notepad.exe' %TEMP%\Plyfiunqnqj.txt
- '<SYSTEM32>\schtasks.exe' /create /tn "svchost" /sc ONLOGON /tr "%TEMP%\zuXWcnPIo7.exe" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "svchost" /sc ONLOGON /tr "<SYSTEM32>\SubDir\Client.exe" /rl HIGHEST /f