Техническая информация
- <SYSTEM32>\tasks\noodles
- %TEMP%\cruopotywire\whitemanthings.exe
- %TEMP%\43722a7fc0724ad481a05a46ed9e754b.xml
- 'ce####1.duckdns.org':5594
- DNS ASK ce####1.duckdns.org
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /Create /TN noodles /XML "%TEMP%\43722a7fc0724ad481a05a46ed9e754b.xml"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /Create /TN noodles /XML "%TEMP%\43722a7fc0724ad481a05a46ed9e754b.xml"
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN noodles /XML "%TEMP%\43722a7fc0724ad481a05a46ed9e754b.xml"