Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\sys32hy.exe
- %APPDATA%\temp\amneziawg-amd64-1.0.0.msi
- %APPDATA%\temp\run.bat
- %APPDATA%\temp\run.vbs
- %APPDATA%\temp\sys32hy.exe
- %APPDATA%\temp\sys32hy.exe
- %APPDATA%\temp\run.vbs
- 'cr#.#ectigo.com':80
- http://cr#.#ectigo.com/SectigoPublicCodeSigningRootR46.crl
- http://oc##.#ectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVD%2BnGf79Hpedv3mhy6uKMVZkPCQQUDyrLIIcouOxvSK4rVKYpqhekzQwCEQDQRhtSn2cYnUN0Tpzv4XKu
- http://cr#.#ectigo.com/SectigoPublicCodeSigningCAR36.crl
- DNS ASK oc##.#ectigo.com
- DNS ASK cr#.#ectigo.com
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\Temp\run.vbs"
- '%WINDIR%\syswow64\msiexec.exe' /i "%APPDATA%\Temp\amneziawg-amd64-1.0.0.msi"
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\Temp\run.bat" " (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C DEL "%APPDATA%\Temp\run.bat"