Техническая информация
- <LS_APPDATA>\cmd.exe /i "<LS_APPDATA>\hta.ini" /quiet
- <SYSTEM32>\msiexec.exe /V
- <SYSTEM32>\msiexec.exe -Embedding 03F8BAD0F50E246E24A4CF9F1703A7FC
- <SYSTEM32>\mshta.exe vbscript:createobject("wscript.shell").run("""iexplore""http://cn##.sjt8.com/info.access/?st#####",0)(window.close)
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://cn##.sjt8.com/info.access/?st#####
- <LS_APPDATA>\hta.ini
- <LS_APPDATA>\exe2.ini
- %WINDIR%\Installer\MSI2.tmp
- %WINDIR%\Installer\46a8d.msi
- <LS_APPDATA>\wget.exe
- %TEMP%\~1.bat
- <LS_APPDATA>\exe1.ini
- <LS_APPDATA>\cmd.exe
- %TEMP%\~1.bat
- 'cn##.sjt8.com':80
- 'localhost':1036
- cn##.sjt8.com/info.access/?st#####
- DNS ASK cn##.sjt8.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''