Техническая информация
- <SYSTEM32>\tasks\deer-neck
- %HOMEPATH%\philadelphia.log.vbs
- %TEMP%\7zsfx000.cmd
- C:\users\public\cork\deer-neck.docx
- %TEMP%\7zsfx000.cmd
- %HOMEPATH%\philadelphia.log.vbs
- DNS ASK de#####l.gortomalo.ru
- '%WINDIR%\syswow64\wscript.exe' %HOMEPATH%\philadelphia.log.vbs
- '%WINDIR%\syswow64\cmd.exe' /c copy /y %HOMEPATH%\philadelphia.log %HOMEPATH%\philadelphia.log.vbs' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c start /b wscript.exe %HOMEPATH%\philadelphia.log.vbs' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /sc minute /mo 10 /tn "deer-neck" /tr "wscript.exe "C:\Users\Public\cork\deer-neck.docx" council //e:VBScript /crept //b council " /F' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c copy /y %HOMEPATH%\philadelphia.log %HOMEPATH%\philadelphia.log.vbs
- '%WINDIR%\syswow64\cmd.exe' /c start /b wscript.exe %HOMEPATH%\philadelphia.log.vbs
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /sc minute /mo 10 /tn "deer-neck" /tr "wscript.exe "C:\Users\Public\cork\deer-neck.docx" council //e:VBScript /crept //b council " /F