Техническая информация
- %WINDIR%\syswow64\cmd.exe
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\d38870f2
- %TEMP%\vmgsgtfmchkhs
- 'ar###itis.org':443
- 'ga###node.io':80
- http://ga###node.io/c2conf
- http://ga###node.io/c2sock
- 'ar###itis.org':443
- DNS ASK ar###itis.org
- DNS ASK ku###lowers.xyz
- DNS ASK ga###node.io
- '%WINDIR%\syswow64\cmd.exe' /c timeout /nobreak /t 3 & fsutil file setZeroData offset=0 length=2616319 "%WINDIR%\SysWOW64\explorer.exe" & erase "%WINDIR%\SysWOW64\explorer.exe" & exit' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\cmd.exe' /c timeout /nobreak /t 3 & fsutil file setZeroData offset=0 length=2616319 "%WINDIR%\SysWOW64\explorer.exe" & erase "%WINDIR%\SysWOW64\explorer.exe" & exit
- '%WINDIR%\syswow64\timeout.exe' /nobreak /t 3