Техническая информация
- %WINDIR%\syswow64\windowspowershell\v1.0\efsane.bat
- %WINDIR%\syswow64\windowspowershell\v1.0\kedi.jpeg
- nul
- %TEMP%\~ptr_b.tmp
- %TEMP%\~ptr_b.bat
- %WINDIR%\temp\client.exe
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- 'localhost':9875
- '31.##.187.119':9875
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- '31.##.187.119':9875
- DNS ASK gi##ub.com
- DNS ASK ra#.####ubusercontent.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'NarratorUIClass' WindowName: ''
- '%WINDIR%\temp\client.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""<SYSTEM32>\WindowsPowerShell\v1.0\Efsane.bat" "
- '<SYSTEM32>\svchost.exe' -k appmodel -p -s camsvc
- '%WINDIR%\syswow64\chcp.com' 65001
- '%WINDIR%\syswow64\timeout.exe' /t 0
- '%WINDIR%\syswow64\cmd.exe' /c exit 0
- '%WINDIR%\syswow64\certutil.exe' -decode "%TEMP%\~ptr_b.tmp" "%TEMP%\~ptr_b.bat"
- '%WINDIR%\temp\client.exe' (со скрытым окном)