Техническая информация
- <SYSTEM32>\tasks\vigfygfcxn
- %WINDIR%\syswow64\explorer.exe
- '%WINDIR%\syswow64\schtasks.exe' /Create /RU "NT AUTHORITY\SYSTEM" /Z /ST 17:34 /tn vigfygfcxn /ET 17:45 /tr "powershell.exe -encodedCommand cgBlAGcAcwB2AHIAMwAyAC4AZQB4AGUAIAAiAGMAOgBcAHAAYwBsAG8AegBcAHkAZwB0AGEALgBkAGwAbAAiA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encodedCommand cgBlAGcAcwB2AHIAMwAyAC4AZQB4AGUAIAAiAGMAOgBcAHAAYwBsAG8AegBcAHkAZwB0AGEALgBkAGwAbAAiAA==' (со скрытым окном)
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\schtasks.exe' /Create /RU "NT AUTHORITY\SYSTEM" /Z /ST 17:34 /tn vigfygfcxn /ET 17:45 /tr "powershell.exe -encodedCommand cgBlAGcAcwB2AHIAMwAyAC4AZQB4AGUAIAAiAGMAOgBcAHAAYwBsAG8AegBcAHkAZwB0AGEALgBkAGwAbAAiA...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encodedCommand cgBlAGcAcwB2AHIAMwAyAC4AZQB4AGUAIAAiAGMAOgBcAHAAYwBsAG8AegBcAHkAZwB0AGEALgBkAGwAbAAiAA==
- '<SYSTEM32>\regsvr32.exe' <Полный путь к файлу>