Техническая информация
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- <DRIVERS>\winhb.sys
- %WINDIR%\temp\cabb9ec.tmp
- %WINDIR%\temp\tarb9ed.tmp
- %WINDIR%\temp\cabbbe1.tmp
- %WINDIR%\temp\tarbbe2.tmp
- %WINDIR%\temp\cabbf6c.tmp
- %WINDIR%\temp\tarbf6d.tmp
- %WINDIR%\temp\cabb9ec.tmp
- %WINDIR%\temp\tarb9ed.tmp
- %WINDIR%\temp\cabbbe1.tmp
- %WINDIR%\temp\tarbbe2.tmp
- %WINDIR%\temp\cabbf6c.tmp
- %WINDIR%\temp\tarbf6d.tmp
- 'localhost':49179
- 'localhost':49181
- 'do######.simpletoolz.fun':443
- 'localhost':49179
- 'localhost':49181
- 'localhost':49182
- 'do######.simpletoolz.fun':443
- DNS ASK do######.simpletoolz.fun
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '<SYSTEM32>\cmd.exe' /C sc create windowsproc type=kernel binpath=<DRIVERS>\winhb.sys (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C sc start windowsproc (со скрытым окном)
- '<SYSTEM32>\sc.exe' create windowsproc type=kernel binpath=<DRIVERS>\winhb.sys
- '<SYSTEM32>\sc.exe' start windowsproc
- '<SYSTEM32>\cmd.exe' /c certutil -hashfile "<Полный путь к файлу>" MD5 | find /i /v "md5" | find /i /v "certutil"
- '<SYSTEM32>\certutil.exe' -hashfile "<Полный путь к файлу>" MD5
- '<SYSTEM32>\find.exe' /i /v "md5"
- '<SYSTEM32>\find.exe' /i /v "certutil"