Техническая информация
- <SYSTEM32>\tasks\winzip updater
- %TEMP%\help.txt
- 'ca####urance.org':80
- 'ca####urance.org':443
- 'pk#.goog':80
- http://pk#.goog/gsr1/gsr1.crt
- 'ca####urance.org':443
- DNS ASK ca####urance.org
- DNS ASK pk#.goog
- '<SYSTEM32>\cmd.exe' /c move %TEMP%\help.txt %HOMEPATH%\temp.ps1' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 "%HOMEPATH%\temp.ps1"' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {EE7ED4D1-BE52-476F-9D7A-CD5DA9DFD432} S-1-5-21-1238866942-1249195528-555854008-1000:ffqzihpohsiz\user:Interactive:[1]
- '<SYSTEM32>\cmd.exe' /c move %TEMP%\help.txt %HOMEPATH%\temp.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 "%HOMEPATH%\temp.ps1"