Техническая информация
- <SYSTEM32>\tasks\dllhost
- <SYSTEM32>\tasks\lsass
- Средство контроля пользовательских учетных записей (UAC)
- %ProgramFiles(x86)%\microsoft analysis services\dllhost.exe
- %LOCALAPPDATA%\mozilla\lsass.exe
- %TEMP%\7z.dll
- %TEMP%\7z.exe
- %TEMP%\axmstsclib.dll
- %TEMP%\ffmpeg.exe
- %LOCALAPPDATA%\microsoft\windows\actioncentercache\windows-systemtoast-securityandmaintenance_10_0.png
- %ProgramFiles(x86)%\microsoft analysis services\dllhost.exe
- %LOCALAPPDATA%\mozilla\lsass.exe
- 'ra#.####ubusercontent.com':443
- 'gi##ub.com':443
- 're#########ets.githubusercontent.com':443
- 'ra#.####ubusercontent.com':443
- 'gi##ub.com':443
- DNS ASK dn#.google
- DNS ASK ra#.####ubusercontent.com
- DNS ASK gi##ub.com
- DNS ASK re#########ets.githubusercontent.com
- 'dn#.google':443
- '18#.#14.96.1':443
- '18#.#14.97.1':443
- '%LOCALAPPDATA%\mozilla\lsass.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' (со скрытым окном)
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted -p -s UmRdpService
- '%WINDIR%\syswow64\reagentc.exe' /disable