Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Initialize' = '%WINDIR%\SysWOW64\rundll32.exe /sta {A762B0C7-5244-4B3E-ADED-D549E9CEA39E} "C"'
- %TEMP%\ixp000.tmp\rl.png
- %TEMP%\ixp000.tmp\bb.exe
- %TEMP%\ixp000.tmp\bb.png
- %LOCALAPPDATA%\microsoft\tapi32.dll
- %LOCALAPPDATA%\microsoft\data.png
- %TEMP%\ixp000.tmp\bb.png
- %TEMP%\ixp000.tmp\bb.exe
- %TEMP%\ixp000.tmp\rl.png
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- '<LOCALNET>..30.6':200
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK lo##o33.com
- '%TEMP%\ixp000.tmp\bb.exe'
- '%WINDIR%\syswow64\cmd.exe' /c cd %LOCALAPPDATA%\Microsoft&&cmd /c reg.exe import data.png (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c reg.exe import data.png
- '%WINDIR%\syswow64\cmd.exe' /c cd %LOCALAPPDATA%\Microsoft&&cmd /c %WINDIR%\SysWOW64\rundll32.exe /sta {A762B0C7-5244-4B3E-ADED-D549E9CEA39E} "Keyboard" (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' import data.png
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\SysWOW64\rundll32.exe /sta {A762B0C7-5244-4B3E-ADED-D549E9CEA39E} "Keyboard"
- '%WINDIR%\syswow64\rundll32.exe' /sta {A762B0C7-5244-4B3E-ADED-D549E9CEA39E} "Keyboard"