Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BSON54AS0D.exe' = '%APPDATA%\BSON54AS0D.exe'
- <SYSTEM32>\tasks\bson54as0d
- %APPDATA%\bson54as0d.exe
- DNS ASK pa###bin.com
- '<SYSTEM32>\schtasks.exe' /Query /TN BSON54AS0D
- '<SYSTEM32>\schtasks.exe' /Create /SC ONLOGON /TN BSON54AS0D /TR %APPDATA%\BSON54AS0D.exe /RU INTERACTIVE /RL HIGHEST /F