Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'SpaceX' = '"%ProgramFiles(x86)%\SpaceX\SpaceXL"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\spacexl.lnk
- %TEMP%\nsida77.tmp\nsisfirewall.dll
- C:\users\public\msi.exe
- C:\users\public\auth.ps1
- %TEMP%\nsne4f2.tmp\nsisfirewall.dll
- %ProgramFiles(x86)%\spacex\spacexl.exe
- %ProgramFiles(x86)%\spacex\ssleay32.dll
- %ProgramFiles(x86)%\spacex\libeay32.dll
- %TEMP%\nsne4f2.tmp\registry.dll
- %TEMP%\nsne4f2.tmp\system.dll
- %TEMP%\id.txt
- %TEMP%\nsne4f2.tmp\nsexec.dll
- nul
- %TEMP%\nsne4f2.tmp\inetc.dll
- %TEMP%\nsida77.tmp\nsisfirewall.dll
- %TEMP%\nsne4f2.tmp\inetc.dll
- %TEMP%\nsne4f2.tmp\nsexec.dll
- %TEMP%\nsne4f2.tmp\nsisfirewall.dll
- %TEMP%\nsne4f2.tmp\registry.dll
- %TEMP%\nsne4f2.tmp\system.dll
- 'sm##.mail.ru':25
- 'id.####teutilities.com':5655
- 'sm##.mail.ru':25
- 'id.####teutilities.com':5655
- 'fi###.#00webhost.com':21
- DNS ASK sm##.mail.ru
- DNS ASK id.####teutilities.com
- DNS ASK fi###.#00webhost.com
- 'C:\users\public\msi.exe'
- '%ProgramFiles(x86)%\spacex\spacexl.exe'
- '%ProgramFiles(x86)%\spacex\spacexl.exe' -second
- '%WINDIR%\syswow64\cmd.exe' /c certutil -f -decodehex %TEMP%\ID.txt %TEMP%\ID.txt>nul' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c certutil -f -decodehex %TEMP%\ID.txt %TEMP%\ID.txt>nul
- '%WINDIR%\syswow64\certutil.exe' -f -decodehex %TEMP%\ID.txt %TEMP%\ID.txt