Техническая информация
- svchost015.exe
- %TEMP%\rarsfx0\soft.exe
- %TEMP%\rarsfx0\mas_aio.cmd
- %TEMP%\svchost015.exe
- %TEMP%\svcbd65.tmp
- nul
- '18#.#56.73.98':80
- DNS ASK drive.usercontent.google.com
- ClassName: 'Edit' WindowName: ''
- '%TEMP%\rarsfx0\soft.exe'
- '%TEMP%\svchost015.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\MAS_AIO.cmd" "
- '<SYSTEM32>\sc.exe' query Null
- '<SYSTEM32>\find.exe' /i "RUNNING"
- '<SYSTEM32>\findstr.exe' /v "$" "MAS_AIO.cmd"
- '<SYSTEM32>\cmd.exe' /c ver
- '<SYSTEM32>\cmd.exe' /S /D /c" echo "AMD64 " "
- '<SYSTEM32>\find.exe' /i "ARM64"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo "%TEMP%\RarSFX0\MAS_AIO.cmd" "
- '<SYSTEM32>\find.exe' /i "%LOCALAPPDATA%\Temp"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -c write-host -back '"Red"' -fore '"white"' '"==== ERROR ===="'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -c write-host -back '"Black"' -fore '"Yellow"' '"Press any key to Go back..."'