Техническая информация
- %TEMP%\ixp000.tmp\f.ps1
- %TEMP%\ixp000.tmp\ff.exe
- %TEMP%\ixp000.tmp\smallbasiclibrary.dll
- %TEMP%\ixp000.tmp\mrkev.bat
- %TEMP%\ixp000.tmp\preput.txt
- %TEMP%\ixp000.tmp\lau.txt
- %TEMP%\ixp000.tmp\in.ps1
- %TEMP%\ixp000.tmp\output.txt
- %TEMP%\ixp000.tmp\peput.txt
- %TEMP%\ixp000.tmp\outputs.txt
- %TEMP%\ixp000.tmp\ff.exe
- %TEMP%\ixp000.tmp\smallbasiclibrary.dll
- %TEMP%\ixp000.tmp\in.ps1
- %TEMP%\ixp000.tmp\lau.txt
- %TEMP%\ixp000.tmp\preput.txt
- %TEMP%\ixp000.tmp\mrkev.bat
- %TEMP%\ixp000.tmp\smallbasiclibrary.dll
- %TEMP%\ixp000.tmp\ff.exe
- %TEMP%\ixp000.tmp\f.ps1
- %TEMP%\ixp000.tmp\output.txt
- %TEMP%\ixp000.tmp\outputs.txt
- %TEMP%\ixp000.tmp\peput.txt
- 'ap#.#asymc.io':443
- 'ap#.#asymc.io':443
- DNS ASK ap#.#asymc.io
- '%TEMP%\ixp000.tmp\ff.exe'
- '<SYSTEM32>\cmd.exe' /c mrkev.bat' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c mrkev.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass .\f.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass .\in.ps1