Техническая информация
- %TEMP%\content\4464-4468-wscript.exe-16-43-47-860.dump
- %APPDATA%\xynmpsanss.js
- %TEMP%\content\4464-4468-wscript.exe-16-43-47-965.dump
- %TEMP%\content\4564-4568-wscript.exe-16-43-51-431.dump
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\notifications\wpndatabase.db-journal
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\notifications\wpndatabase.db
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\notifications\wpndatabase.db-wal
- %ALLUSERSPROFILE%\microsoft\windows\onesettings\config.json
- %ALLUSERSPROFILE%\microsoft\windows\onesettings\asap_cloudpolicy.json
- %ALLUSERSPROFILE%\microsoft\windows\onesettings\cortanauwp.json
- %ALLUSERSPROFILE%\microsoft\windows\onesettings\ctac.json
- %ALLUSERSPROFILE%\microsoft\windows\onesettings\directxdbversion.json
- 'pa###ball.lt':80
- http://pa###ball.lt/wp-includes/build.exe
- DNS ASK pa###ball.lt
- '<SYSTEM32>\wscript.exe' //B "%APPDATA%\XYNmPsanSS.js"
- '<SYSTEM32>\mitigationscanner.exe'