Техническая информация
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %LOCALAPPDATA%\Tempfghkl045kfdlkdf4j3igo.lnk
- C:\users\public\.desktop\fgkjg9grjk9jkgrji394jgkfdgjllj3.dll
- %LOCALAPPDATA%\tempfghkl045kfdlkdf4j3igo.lnk
- C:\users\public\.desktop\fgkjg9grjk9jkgrji394jgkfdgjllj3.dll в %TEMP%\jnpaiiqqj1gdkjkd392jgk.dll
- %TEMP%\jnpaiiqqj1gdkjkd392jgk.dll в %TEMP%\nbpf4foon0r
- DNS ASK mi##xing.pw
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %LOCALAPPDATA%\Tempfghkl045kfdlkdf4j3igo.lnk' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' /u /s "C:\Users\Public\.desktop\fgkjg9grjk9jkgrji394jgkfdgjllj3.dll"' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' /u /s "C:\Users\Public\.desktop\fgkjg9grjk9jkgrji394jgkfdgjllj3.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /u /s "%TEMP%\\jnpaiiqqj1gdkjkd392jgk.dll"