Техническая информация
- <SYSTEM32>\tasks\hiveuploadtask
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\ntuser.dat.LOG4 //e:VBScript delighted delicious demanded //b
- %HOMEPATH%\ntuser.dat.log4
- 'de#######.delicious.billyhot.ru':80
- http://13#.#84.6.209/gasoline.ace
- DNS ASK de#######.delicious.billyhot.ru
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\ntuser.dat.LOG4 //e:VBScript delighted delicious demanded //b' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {0C06DFDE-06C1-432A-918C-45326C6A9092} S-1-5-21-1960123792-2022915161-3775307078-1001:vpkncteitm\user:Interactive:[1]