Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%HOMEPATH%\c3'"
- '<SYSTEM32>\taskkill.exe' /F /IM cmd.exe
- %HOMEPATH%\c3\go.bat
- nul
- %HOMEPATH%\c3\z2aqzlx37f.bat
- %HOMEPATH%\c3\go.bat
- %HOMEPATH%\c3\z2aqzlx37f.bat
- '17#.#78.173.103':80
- 'gi##ub.com':443
- 'ob#####.#ithubusercontent.com':443
- http://17#.#78.173.103/go.bat
- http://17#.#78.173.103/c.bat
- 'gi##ub.com':443
- 'ob#####.#ithubusercontent.com':443
- DNS ASK au##.c3pool.org
- DNS ASK gi##ub.com
- DNS ASK ob#####.#ithubusercontent.com
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c %HOMEPATH%\c3\go.bat
- '<SYSTEM32>\sc.exe' stop XLServicePlatform
- '<SYSTEM32>\sc.exe' delete XLServicePlatform
- '<SYSTEM32>\cmd.exe' /c %HOMEPATH%\c3\z2AqzLx37F.bat
- '<SYSTEM32>\attrib.exe' +h +s "%HOMEPATH%\c3\go.bat"
- '<SYSTEM32>\attrib.exe' +h +s "%HOMEPATH%\c3\z2AqzLx37F.bat"
- '<SYSTEM32>\icacls.exe' %HOMEPATH%\c3\ /deny Everyone:(RX)
- '<SYSTEM32>\attrib.exe' +h +s "%HOMEPATH%\c3\."