Техническая информация
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Services.exe' = '%TEMP%\Windows Services.exe'
- <SYSTEM32>\tasks\limerat-admin
- %TEMP%\windows services.exe
- %APPDATA%\wyuwdflj_2023_5_8
- %TEMP%\windows services.exe
- DNS ASK gi###lue.com
- '%TEMP%\windows services.exe'
- '<SYSTEM32>\schtasks.exe' /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'%TEMP%\Windows Services.exe'"' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'%TEMP%\Windows Services.exe'"