Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\windows defender.exe
- %TEMP%\ixp000.tmp\7z.exe
- %TEMP%\ixp000.tmp\crypter.bat
- %TEMP%\ixp000.tmp\decryptor.exe
- %TEMP%\ixp000.tmp\entschlГјsslungsschutz.exe
- %TEMP%\ixp000.tmp\installer.bat
- %TEMP%\ixp000.tmp\test.zip
- %TEMP%\ixp000.tmp\windows defender.exe
- %TEMP%\ixp000.tmp\porno.mp4
- %TEMP%\ixp000.tmp\meldung.exe
- %APPDATA%\networktraffic\crypter.bat
- %APPDATA%\networktraffic\meldung.exe
- %APPDATA%\networktraffic\decryptor.exe
- %APPDATA%\networktraffic\7z.exe
- %APPDATA%\networktraffic\test.zip
- %TEMP%\ixp000.tmp\meldung.exe
- %TEMP%\ixp000.tmp\porno.mp4
- %TEMP%\ixp000.tmp\windows defender.exe
- %TEMP%\ixp000.tmp\test.zip
- %TEMP%\ixp000.tmp\installer.bat
- %TEMP%\ixp000.tmp\entschlГјsslungsschutz.exe
- %TEMP%\ixp000.tmp\decryptor.exe
- %TEMP%\ixp000.tmp\crypter.bat
- %TEMP%\ixp000.tmp\7z.exe
- ClassName: 'JFWUI2' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c Installer.bat (со скрытым окном)
- '%ProgramFiles(x86)%\windows media player\wmplayer.exe' /Play -Embedding
- '<SYSTEM32>\cmd.exe'