Техническая информация
- %TEMP%\fhackdat\4063\res\13146.exe
- %TEMP%\fhackdat\4063\res\_fart.~
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\main.bat.tmp
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\main.bat.da
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\main.bat
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\owo.flx
- %TEMP%\ytmp\t22591.bat
- %TEMP%\ytmp\t22643.exe
- %TEMP%\splash.gif
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\owo.bat.tmp
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\owo.bat
- %TEMP%\setup.tp
- %TEMP%\fhackdat\4063\res\launch\icon.ico
- %TEMP%\fhackdat\4063\res\launch\win.exe
- %TEMP%\pid.tp
- <Текущая директория>\owo.txt
- %TEMP%\ytmp\tmp1552.bat
- %TEMP%\ytmp\t2775.exe
- nul
- %TEMP%\ytmp\t2726.bat
- %TEMP%\afolder\fart.exe
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\main.flx
- %TEMP%\fhackdat\4063\res\launch.exe
- %TEMP%\fhackdat\4063\res\main.flx
- %TEMP%\fhackdat\4063\res\manifest.txt
- %TEMP%\fhackdat\4063\res\owo.flx
- %TEMP%\fhackdat\4063\res\setup.bat
- %TEMP%\fhackdat\4063\res\splash.exe
- %TEMP%\dir.tp
- %TEMP%\ytmp\tmp2981.exe
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\owo.bat.da
- %TEMP%\script.tp
- %TEMP%\fhackdat\4063\res\dead.mp3
- %TEMP%\fhackdat\4063\res\function.ico
- %TEMP%\fhackdat\4063\res\icon.png
- %TEMP%\fhackdat\4063\res\other.bat
- %TEMP%\fhackdat\4063\res\sayonara.hta
- %TEMP%\fhackdat\4063\res\sayonara.ico
- %TEMP%\fhackdat\4063\res\splash.jpg
- %TEMP%\fhackdat\4063\res\contents.dk
- %TEMP%\fhackdat\4063\res\banner.txt
- %TEMP%\winv.tp
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\main.flx
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\main.bat.da
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\main.bat.tmp
- %TEMP%\afolder\fart.exe
- %TEMP%\ytmp\t2726.bat
- %TEMP%\ytmp\t2775.exe
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\owo.flx
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\owo.bat.da
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\owo.bat.tmp
- %TEMP%\ytmp\t22591.bat
- %TEMP%\ytmp\t22643.exe
- %TEMP%\dir.tp
- %TEMP%\ytmp\tmp2981.exe
- %TEMP%\fhackdat\4063\res\contents.dk в %TEMP%\fhackdat\4063\res\contents.exe
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\main.flx
- %TEMP%\fhackdat\4063\res\_fart.~
- %TEMP%\afolder\fart.exe
- %LOCALAPPDATA%\microsoft\windows\powershell\13146\main\idk\owo.flx
- ClassName: 'AutoHotkey' WindowName: '%TEMP%\fhackdat\4063\res\splash.exe'
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'AutoHotkey' WindowName: '%TEMP%\fhackdat\4063\res\contents.exe'
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" MAIKKJ I
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" "WERTQY" "bat"
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" "HTTHARYUGOCXZSL6" "/"
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" "UYAHJHAHYFSWPZXVNFN" "+"
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" UOAQW4 k
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" CUZMAOT z
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" UAYAJAKALA j
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" AOTQW L
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" YTAREGAGAG A
- '%TEMP%\fhackdat\4063\res\launch.exe' "<Текущая директория>" "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk"
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" "5476479820809" "b85"
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" "@fluxia" "res"
- '%TEMP%\fhackdat\4063\res\13146.exe' 001 "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx"
- '%TEMP%\fhackdat\4063\res\contents.exe'
- '%TEMP%\fhackdat\4063\res\launch\win.exe'
- '%TEMP%\fhackdat\4063\res\splash.exe'
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" "MANNAUHF" "."
- '%TEMP%\fhackdat\4063\res\13146.exe' 001 "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\owo.flx"
- '%TEMP%\afolder\fart.exe' -r "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" "__t2w" "="
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\fhackdat\4063\res\setup.bat" 4063' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\ytmp\t22591.bat" "%TEMP%\fhackdat\4063\res\13146.exe" 001 "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\owo.flx" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +r +h +s "%TEMP%\fhackdat\4063\res\launch" /d /s' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +r +h +s "%TEMP%\fhackdat\4063" /d /s' (со скрытым окном)
- '%TEMP%\fhackdat\4063\res\launch\win.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\ytmp\t2726.bat" "%TEMP%\fhackdat\4063\res\13146.exe" 001 "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c %LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.bat 2>nul' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +r +h +s "%TEMP%\fhackdat\4063" /d /s
- '%WINDIR%\syswow64\cmd.exe' /c if exist "%TEMP%\ytmp\tmp2981.exe" del "%TEMP%\ytmp\tmp2981.exe"
- '%WINDIR%\syswow64\cmd.exe' /c if exist "%TEMP%\ytmp\tmp1552.bat" del "%TEMP%\ytmp\tmp1552.bat"
- '%WINDIR%\syswow64\cmd.exe' /c attrib +h %TEMP%\ytmp
- '%WINDIR%\syswow64\cmd.exe' /c if not exist "%TEMP%\ytmp" mkdir "%TEMP%\ytmp"
- '%WINDIR%\syswow64\cmd.exe' /c if not exist "%TEMP%\afolder" mkdir "%TEMP%\afolder"
- '%WINDIR%\syswow64\attrib.exe' +r +h +s "%TEMP%\fhackdat\4063\res\launch" /d /s
- '%WINDIR%\syswow64\cmd.exe' /c %LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.bat 2>nul
- '%WINDIR%\syswow64\cmd.exe' /c attrib +r +h +s "%TEMP%\fhackdat\4063\res\launch" /d /s
- '%WINDIR%\syswow64\cscript.exe' /B /E:vbs "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\\owo.bat.da"
- '%WINDIR%\syswow64\findstr.exe' /I /B /N ":+res:b[0-9]*:[0-9]*:owo.bat:" "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\owo.flx"
- '%WINDIR%\syswow64\findstr.exe' "+res" "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\owo.flx"
- '%WINDIR%\syswow64\cmd.exe' /c findstr "+res" "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\owo.flx"
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\ytmp\t22591.bat" "%TEMP%\fhackdat\4063\res\13146.exe" 001 "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\owo.flx" "
- '%WINDIR%\syswow64\cscript.exe' /B /E:vbs "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\\main.bat.da"
- '%WINDIR%\syswow64\findstr.exe' /I /B /N ":+res:b[0-9]*:[0-9]*:main.bat:" "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx"
- '%WINDIR%\syswow64\findstr.exe' "+res" "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx"
- '%WINDIR%\syswow64\cmd.exe' /c findstr "+res" "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx"
- '%WINDIR%\syswow64\attrib.exe' +h %TEMP%\ytmp
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\ytmp\t2726.bat" "%TEMP%\fhackdat\4063\res\13146.exe" 001 "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk\main.flx" "
- '%WINDIR%\syswow64\attrib.exe' +r +h +s "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main\idk" /d /s
- '%WINDIR%\syswow64\attrib.exe' +r +h +s "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146\main" /d /s
- '%WINDIR%\syswow64\attrib.exe' +r +h +s "%LOCALAPPDATA%\Microsoft\Windows\PowerShell\13146" /d /s
- '%WINDIR%\syswow64\findstr.exe' /I /R "[0-9][0-9]*\.exe$"
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" dir /B /A:-D "*.exe" "
- '%WINDIR%\syswow64\attrib.exe' +r +h +s "%TEMP%\fhackdat\4063" /d /s
- '%WINDIR%\syswow64\cmd.exe' /c dir /B /A:-D "*.exe" | findstr /I /R "[0-9][0-9]*\.exe$"
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\fhackdat\4063\res\setup.bat" 4063
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\ytmp\tmp1552.bat "%TEMP%\fhackdat\4063\res\launch\win.exe"
- '%WINDIR%\syswow64\cmd.exe' /c ver