Техническая информация
- <SYSTEM32>\tasks\updates\azxshk
- '' (загружен из сети Интернет)
- 'C:\users\public\908.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath 'C:\Users\Public\908.exe'
- 908.exe
- C:\users\public\908.exe
- %APPDATA%\azxshk.exe
- %TEMP%\tmpe2cf.tmp
- %APPDATA%\azxshk.exe
- %TEMP%\tmpe2cf.tmp
- http://bi#.ly/3iMEVFK
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- http://ap#.#pify.org/
- DNS ASK bi#.ly
- DNS ASK u.##knik.io
- DNS ASK st####.rapidssl.com
- DNS ASK oc##.thawte.com
- DNS ASK ap#.#pify.org
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\AzXshK" /XML "%TEMP%\tmpE2CF.tmp"' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\AzXshK" /XML "%TEMP%\tmpE2CF.tmp"