Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\AsuRiiixeRFTClgZVZp] 'ImagePath' = '%TEMP%\AsuRiiixeRFTClgZVZp'
- 'AsuRiiixeRFTClgZVZp' %TEMP%\AsuRiiixeRFTClgZVZp
- %WINDIR%\softwaredistribution\download\slightskantutero.sys
- %WINDIR%\softwaredistribution\download\slightskantutero.exe
- %TEMP%\asuriiixerftclgzvzp
- %WINDIR%\temp\udd7d3b.tmp
- %WINDIR%\temp\udd7d3b.tmp
- 'ra#.####ubusercontent.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com
- '%WINDIR%\softwaredistribution\download\slightskantutero.exe' %WINDIR%\SoftwareDistribution\Download\SLIGHTSKANTUTERO.sys
- '%WINDIR%\softwaredistribution\download\slightskantutero.exe' %WINDIR%\SoftwareDistribution\Download\SLIGHTSKANTUTERO.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c cls