Техническая информация
- <SYSTEM32>\tasks\updates\jcjxtjtrt
- %APPDATA%\jcjxtjtrt.exe
- %TEMP%\tmp10c2.tmp
- %TEMP%\tmp10c2.tmp
- http://2n#.co/1v22h7.html
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://oc##.#ectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEGmjTouN%2FW5s3CDseaiw7qE%3D
- DNS ASK 2n#.co
- DNS ASK ip###ger.org
- DNS ASK microsoft.com
- DNS ASK oc##.#ectigo.com
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\jcjXtJTRt" /XML "%TEMP%\tmp10C2.tmp"' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\jcjXtJTRt" /XML "%TEMP%\tmp10C2.tmp"