Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent 796a425831b6aadb
- <SYSTEM32>\tasks\rovwer.exe
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\explorer.exe
- iexplore.exe
- %APPDATA%\catitrv
- %APPDATA%\hjgrecf
- %TEMP%\aa52.exe
- %TEMP%\b667dbdcd8\rovwer.exe
- %APPDATA%\catitrv
- %APPDATA%\hjgrecf
- 'o3####s3sn6xou.com':80
- 'th#####ncondition.com':443
- '77.##.134.249':80
- '17#.#13.115.201':80
- http://77.##.134.249/vr/movie.exe
- http://o3####s3sn6xou.com/
- http://17#.#13.115.201/3g4mn5s/index.php
- 'th#####ncondition.com':443
- DNS ASK o3####s3sn6xou.com
- DNS ASK th#####ncondition.com
- '%APPDATA%\catitrv'
- '%TEMP%\aa52.exe'
- '%TEMP%\b667dbdcd8\rovwer.exe'
- '%APPDATA%\catitrv' ' (со скрытым окном)
- '%TEMP%\b667dbdcd8\rovwer.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 1 /TN rovwer.exe /TR "%TEMP%\b667dbdcd8\rovwer.exe" /F' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {FB9EFC73-525C-4F2D-8446-CEEC677D5F5E} S-1-5-21-1960123792-2022915161-3775307078-1001:psgbtquifooz\user:Interactive:[1]
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\explorer.exe'
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 1 /TN rovwer.exe /TR "%TEMP%\b667dbdcd8\rovwer.exe" /F