Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\SysTelemetryAgent] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\SysTelemetryAgent] 'ImagePath' = '<SYSTEM32>\svchost.exe -k TelemetryGroup'
- [HKLM\SYSTEM\CurrentControlSet\Services\SysTelemetryAgent\Parameters] 'ServiceDll' = '<SYSTEM32>\ar-SA\telemetryui.mfl'
- 'SysTelemetryAgent' <SYSTEM32>\svchost.exe -k TelemetryGroup
- <SYSTEM32>\windowspowershell\v1.0\cer996d.tmp
- <SYSTEM32>\windowspowershell\v1.0\cer996e.tmp
- <SYSTEM32>\ar-sa\telemetryui.mfl
- conout$
- <SYSTEM32>\windowspowershell\v1.0\cer996d.tmp
- <SYSTEM32>\windowspowershell\v1.0\cer996e.tmp
- '15#.#01.1.91':443
- DNS ASK fi#####.###tings.services.mozilla.com
- '<SYSTEM32>\cmd.exe' /c certutil -addstore ROOT .\cer996D.tmp
- '<SYSTEM32>\certutil.exe' -addstore ROOT .\cer996D.tmp
- '<SYSTEM32>\cmd.exe' /c certutil -addstore CA .\cer996E.tmp
- '<SYSTEM32>\certutil.exe' -addstore CA .\cer996E.tmp