Техническая информация
- <SYSTEM32>\tasks\systemfile
- %TEMP%\windows\systemfile.exe
- %APPDATA%\windows\telemetry\sihost64.exe
- %APPDATA%\windows\libs\wr64.sys
- '%TEMP%\windows\systemfile.exe'
- '%APPDATA%\windows\telemetry\sihost64.exe'
- '%APPDATA%\windows\telemetry\sihost64.exe' ' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' cmd /c powershell -EncodedCommand "QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwAJABlAG4AdgA6AFMAeQBzAH...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand "QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwAJABlAG4AdgA6AFMAeQBzAHQAZQBtAEQAcgBpAHYA...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand "QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4ARQB4AHQAZQBuAHMAaQBvAG4AIABAACgAJwBlAHgAZQAnACwAJwBkAGwAbAAnACkAIAAtAEYAbwByAGMAZQA="
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn "systemfile" /tr "%TEMP%\Windows\systemfile.exe"
- '<SYSTEM32>\schtasks.exe' /create /f /sc onlogon /rl highest /tn "systemfile" /tr "%TEMP%\Windows\systemfile.exe"
- '<SYSTEM32>\cmd.exe' cmd /c "%TEMP%\Windows\systemfile.exe"