Техническая информация
- <DRIVERS>\etc\hosts.ics
- %WINDIR%\server.crt
- %TEMP%\aut9bbf.tmp
- %TEMP%\unkclub_loader.exe
- <DRIVERS>\etc\hosts.ics
- <DRIVERS>\etc\hosts
- %WINDIR%\server.crt
- %TEMP%\aut9bbf.tmp
- 'ra#.####ubusercontent.com':443
- '13.##3.66.168':80
- http://13.##3.66.168/server.crt
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -Command "Import-Certificate -FilePath '%WINDIR%\server.crt' -CertStoreLocation 'Cert:\LocalMachine\Root' -ErrorAction SilentlyContinue"
- '%TEMP%\unkclub_loader.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -Command "Import-Certificate -FilePath '%WINDIR%\server.crt' -CertStoreLocation 'Cert:\LocalMachine\Root' -ErrorAction SilentlyContinue" (со скрытым окном)