Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '<Текущая директория>\' -ErrorAction SilentlyContinue; Add-MpPreference -ExclusionProcess 'Autok...
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '.exe;.bat;.cmd;.vbs'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '.exe;.bat;.cmd;.vbs'
- %HOMEPATH%\desktop\canhtrang.lnk
- %WINDIR%\syswow64\windowspowershell\v1.0\config\tbroad.txt
- 'li#.##nhtrang.com':80
- 'drive.google.com':443
- 'drive.usercontent.google.com':443
- 'drive.google.com':443
- 'drive.usercontent.google.com':443
- DNS ASK li#.##nhtrang.com
- DNS ASK ca###rang.com
- DNS ASK drive.google.com
- DNS ASK drive.usercontent.google.com
- ClassName: 'Sword3 Class' WindowName: ''