Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\services\RemoteDesktopDownload\Parameters] 'ServiceDll' = '<SYSTEM32>\RemoteDesktopDownload.dll'
- [HKLM\System\CurrentControlSet\Services\RemoteDesktopDownload] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\RemoteDesktopDownload] 'ImagePath' = '<SYSTEM32>\svchost.exe -k RemoteDesktopDownload'
- 'RemoteDesktopDownload' <SYSTEM32>\svchost.exe -k RemoteDesktopDownload
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "<SYSTEM32>"
- <SYSTEM32>\remotedesktopdownload.dll
- %WINDIR%\cmsyfqq.bin
- 'gr###fy.link':443
- 'gr###fy.link':443
- DNS ASK gr###fy.link
- '<SYSTEM32>\svchost.exe' -k RemoteDesktopDownload
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "<SYSTEM32>" (со скрытым окном)