Техническая информация
- <SYSTEM32>\tasks\hiveuploadtask
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\descendant.log //e:VBScript demonstrate deity definition //b
- %HOMEPATH%\descendant.log
- 'de#####rate.lotorgas.ru':80
- DNS ASK de#####rate.lotorgas.ru
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\descendant.log //e:VBScript demonstrate deity definition //b' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {AB17C5DE-04D4-4C21-BB93-73CC3FCEA1A6} S-1-5-21-1960123792-2022915161-3775307078-1001:xsceymxmg\user:Interactive:[1]