Техническая информация
- %TEMP%\4b9a106e76\nbveek.exe
- %TEMP%\960123792202
- %TEMP%\960123792202
- '62.##4.41.92':80
- http://62.##4.41.92/n9dks3s/index.php
- '%TEMP%\4b9a106e76\nbveek.exe'
- '%TEMP%\4b9a106e76\nbveek.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /k echo Y|CACLS "nbveek.exe" /P "user:N"&&CACLS "nbveek.exe" /P "user:R" /E&&echo Y|CACLS "..\4b9a106e76" /P "user:N"&&CACLS "..\4b9a106e76" /P "user:R" /E&&Exit' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /k echo Y|CACLS "nbveek.exe" /P "user:N"&&CACLS "nbveek.exe" /P "user:R" /E&&echo Y|CACLS "..\4b9a106e76" /P "user:N"&&CACLS "..\4b9a106e76" /P "user:R" /E&&Exit
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo Y"
- '%WINDIR%\syswow64\cacls.exe' "nbveek.exe" /P "user:N"
- '%WINDIR%\syswow64\cacls.exe' "nbveek.exe" /P "user:R" /E
- '%WINDIR%\syswow64\cacls.exe' "..\4b9a106e76" /P "user:N"
- '%WINDIR%\syswow64\cacls.exe' "..\4b9a106e76" /P "user:R" /E