Техническая информация
- <SYSTEM32>\tasks\lime_0.5
- %HOMEPATH%\myfolder\taskhostex.exe
- %HOMEPATH%\myfolder\taskhostex.exe
- DNS ASK pa###bin.com
- '%HOMEPATH%\myfolder\taskhostex.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /f /sc minute /mo 1 /tn Lime_0.5 /tr %HOMEPATH%\MyFolder\taskhostex.exe' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /f /sc minute /mo 1 /tn Lime_0.5 /tr %HOMEPATH%\MyFolder\taskhostex.exe
- '<SYSTEM32>\taskeng.exe' {BD385D64-23B6-4FA8-8A3C-D37D2E4AD74D} S-1-5-21-1960123792-2022915161-3775307078-1001:dxvzoisreyig\user:Interactive:[1]