Техническая информация
- <SYSTEM32>\tasks\microsoft compatibility appraiser
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\Searches\destitute.lnk //e:VBScript //b
- '<SYSTEM32>\ipconfig.exe' /flushdns
- %HOMEPATH%\searches\destitute.lnk
- '0.###.158.241':80
- DNS ASK de####e.brontaga.ru
- '<SYSTEM32>\ipconfig.exe' /flushdns' (со скрытым окном)
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\Searches\destitute.lnk //e:VBScript //b' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {509A5F04-BBAC-484D-9915-87F32AEA8B42} S-1-5-21-1960123792-2022915161-3775307078-1001:wexaxmg\user:Interactive:[1]
- '%ProgramFiles%\microsoft office\office14\winword.exe' /Automation -Embedding