Техническая информация
- <SYSTEM32>\tasks\feg1qnjw.exe
- %WINDIR%\syswow64\svchost.exe
- %LOCALAPPDATA%\eqppkzmqq\python313.dll
- %LOCALAPPDATA%\eqppkzmqq\pythonw.exe
- %LOCALAPPDATA%\eqppkzmqq\vcruntime140.dll
- %APPDATA%\xd8ioypssk\python313.dll
- %APPDATA%\xd8ioypssk\vcruntime140.dll
- %APPDATA%\xd8ioypssk\feg1qnjw.exe
- '15#.90.7.93':56001
- '15#.90.7.93':56002
- '15#.90.7.93':56003
- '%LOCALAPPDATA%\eqppkzmqq\pythonw.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "fEG1QnjW.exe" /tr "\"%APPDATA%\XD8iOYpssK\fEG1QnjW.exe\"" /sc onlogon /rl highest /ru BUILTIN\Users (со скрытым окном)
- '%WINDIR%\syswow64\svchost.exe'