Техническая информация
- <SYSTEM32>\tasks\deep-settled
- %TEMP%\7zsfx000.cmd
- C:\users\public\deepmouthed\deep-settled.mp3
- %TEMP%\7zsfx000.cmd
- %HOMEPATH%\join.log.vbs
- %HOMEPATH%\join.log в %HOMEPATH%\join.log.vbs
- DNS ASK de######nching.gortomalo.ru
- '%WINDIR%\syswow64\wscript.exe' "%HOMEPATH%\join.log.vbs"
- '%WINDIR%\syswow64\cmd.exe' /c rename %HOMEPATH%\join.log join.log.vbs' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c start /b %HOMEPATH%\join.log.vbs' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /sc minute /mo 8 /tn "deep-settled" /tr "wscript.exe "C:\Users\Public\\deepmouthed\deep-settled.mp3" cracker /cosy //b /cottage //e:VBScript /crept cracker " /F' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c rename %HOMEPATH%\join.log join.log.vbs
- '%WINDIR%\syswow64\cmd.exe' /c start /b %HOMEPATH%\join.log.vbs
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /sc minute /mo 8 /tn "deep-settled" /tr "wscript.exe "C:\Users\Public\\deepmouthed\deep-settled.mp3" cracker /cosy //b /cottage //e:VBScript /crept cracker " /F