Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent e4a54150fa65b156
- imposed.com
- %TEMP%\version
- %TEMP%\entire
- %TEMP%\accessing
- %TEMP%\frequently
- %TEMP%\blade
- %TEMP%\et
- %TEMP%\peripherals
- %TEMP%\frequently.cmd
- %TEMP%\390641\imposed.com
- %TEMP%\390641\b
- %APPDATA%\assftvh
- %APPDATA%\assftvh
- %TEMP%\390641\b
- %TEMP%\390641\imposed.com
- 'qu###umqube.org':80
- 'qu###umqube.org':443
- 'in###ixus.org':80
- 'in###ixus.org':443
- http://qu###umqube.org/index.php
- http://in###ixus.org/index.php
- DNS ASK tV#############jWdOBJOajLc.tVbpvlpuypYopkFjWdOBJOajLc
- DNS ASK qu###umqube.org
- DNS ASK in###ixus.org
- '%TEMP%\390641\imposed.com' B
- '%TEMP%\390641\imposed.com'
- '%WINDIR%\syswow64\cmd.exe' /c copy Frequently Frequently.cmd & Frequently.cmd (со скрытым окном)
- '%WINDIR%\syswow64\tasklist.exe'
- '%WINDIR%\syswow64\findstr.exe' /I "wrsa opssvc"
- '%WINDIR%\syswow64\findstr.exe' "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth"
- '%WINDIR%\syswow64\cmd.exe' /c md 390641
- '%WINDIR%\syswow64\findstr.exe' /V "ConventionTroopsStudiedTooth" Version
- '%WINDIR%\syswow64\cmd.exe' /c copy /b ..\Accessing + ..\Entire + ..\Peripherals + ..\Et B
- '%WINDIR%\syswow64\choice.exe' /d y /t 5