Техническая информация
- <SYSTEM32>\tasks\hiveuploadtask
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\ntuser.dat.LOG4 //e:VBScript delirium detail deserted //b
- %HOMEPATH%\ntuser.dat.log4
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK de######.detail.billyhot.ru
- '<SYSTEM32>\taskeng.exe' {1FBE1944-8379-409A-873E-D75A3860192F} S-1-5-21-3691498038-2086406363-2140527554-1000:qhrcrejjvf\user:Interactive:[1]
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\ntuser.dat.LOG4 //e:VBScript delirium detail deserted //b (со скрытым окном)