Техническая информация
- <SYSTEM32>\tasks\explothe.exe
- %TEMP%\fefffe8cea\explothe.exe
- '77.#1.124.1':80
- '<DNS_SERVER>':53
- '%TEMP%\fefffe8cea\explothe.exe'
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 1 /TN explothe.exe /TR "%TEMP%\fefffe8cea\explothe.exe" /F (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /k echo Y|CACLS "explothe.exe" /P "user:N"&&CACLS "explothe.exe" /P "user:R" /E&&echo Y|CACLS "..\fefffe8cea" /P "user:N"&&CACLS "..\fefffe8cea" /P "user:R" /E&&Exit (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo Y"
- '%WINDIR%\syswow64\cacls.exe' "explothe.exe" /P "user:N"
- '%WINDIR%\syswow64\cacls.exe' "explothe.exe" /P "user:R" /E
- '%WINDIR%\syswow64\cacls.exe' "..\fefffe8cea" /P "user:N"
- '%WINDIR%\syswow64\cacls.exe' "..\fefffe8cea" /P "user:R" /E
- '%TEMP%\fefffe8cea\explothe.exe' (со скрытым окном)