Техническая информация
- [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '%WINDIR%\svchost.exe'
- %WINDIR%\svchost.exe
- %WINDIR%\csrss.exe
- %WINDIR%\victim - lgqhnriw.txt
- '17#.#21.216.113':21
- ClassName: '' WindowName: 'TeamViewer'
- ClassName: 'edit' WindowName: ''
- ClassName: '' WindowName: 'TeamViewer - Registro de sucesos de la transferencia de archivos'
- ClassName: '' WindowName: 'SesiГіn esponsorizada'
- '%WINDIR%\csrss.exe' --pw "MTIzNDU2"
- '%WINDIR%\csrss.exe' --pw "MTIzNDU2" (со скрытым окном)