Техническая информация
- <SYSTEM32>\tasks\regidlebackup
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\Downloads\desert.log //e:VBScript /deprive /decidedly /decision //b
- %HOMEPATH%\downloads\desert.log
- 'de####e.lotorgas.ru':80
- DNS ASK de####e.lotorgas.ru
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\Downloads\desert.log //e:VBScript /deprive /decidedly /decision //b' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {13BD1DFA-5364-47E2-BA3F-8CE0974519B7} S-1-5-21-1960123792-2022915161-3775307078-1001:tpfhikjbay\user:Interactive:[1]