Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'system.exe' = '"C:\ProgramsData\app.exe"'
- <SYSTEM32>\tasks\system.exe
- <SYSTEM32>\tasks\windowssystemhost
- C:\programsdata\app.exe
- 'cd#.##scordapp.com':443
- 'ip##pi.com':80
- '19#.#6.237.44':1133
- 'cd#.##scordapp.com':443
- '19#.#6.237.44':1133
- DNS ASK cd#.##scordapp.com
- DNS ASK ip##pi.com
- 'C:\programsdata\app.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "WINDOWSSYSTEMHOST" /tr "C:\ProgramsData\app.exe" /sc MINUTE /MO 1' (со скрытым окном)
- 'C:\programsdata\app.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "system.exe" /sc ONLOGON /tr "C:\ProgramsData\app.exe" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "WINDOWSSYSTEMHOST" /tr "C:\ProgramsData\app.exe" /sc MINUTE /MO 1
- '<SYSTEM32>\taskeng.exe' {956635EB-1E75-41BF-8585-8A936B2853F7} S-1-5-21-1960123792-2022915161-3775307078-1001:ihxjdsuidn\user:Interactive:[1]