Техническая информация
- <SYSTEM32>\tasks\nxfmkjg
- %ALLUSERSPROFILE%\installer\nxfmkjg.exe
- %TEMP%\tmp3fdd.tmp.bat
- nul
- %ALLUSERSPROFILE%\screen.jpg
- %ALLUSERSPROFILE%\installer\xmr.exe
- %ALLUSERSPROFILE%\installer\xmr.exe
- 'c1#####.#ostde22.fornex.host':80
- 'mi######tvisualstudio.wtf':80
- http://c1#####.#ostde22.fornex.host/setupis.exe
- http://mi######tvisualstudio.wtf/main.php
- http://mi######tvisualstudio.wtf/dl.php
- DNS ASK c1#####.#ostde22.fornex.host
- DNS ASK mi######tvisualstudio.wtf
- '%ALLUSERSPROFILE%\installer\nxfmkjg.exe'
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 3 /tn "NXFMKJG" /tr "%ALLUSERSPROFILE%\Installer\NXFMKJG.exe" /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp3FDD.tmp.bat""
- '<SYSTEM32>\timeout.exe' 3
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 3 /tn "NXFMKJG" /tr "%ALLUSERSPROFILE%\Installer\NXFMKJG.exe" /f