Техническая информация
- <SYSTEM32>\tasks\uycgkosw04os
- C:\users\public\bot_log.txt
- %APPDATA%\microsoft\windows\qgwcsiyeuk0g\nvdisplay.container.exe
- 'di##ord.com':443
- 'ga####y.discord.gg':443
- 'di##ord.com':443
- 'ga####y.discord.gg':443
- DNS ASK di##ord.com
- DNS ASK ga####y.discord.gg
- ClassName: 'runtimebroker.exe' WindowName: ''
- '<SYSTEM32>\wbem\wmic.exe' /format:list "SELECT ProcessorId FROM Win32_Processor"
- '<SYSTEM32>\wbem\wmic.exe' /format:list "SELECT SerialNumber FROM Win32_BaseBoard"
- '<SYSTEM32>\wbem\wmic.exe' /format:list "SELECT SerialNumber FROM Win32_BIOS"
- '<SYSTEM32>\query.exe' session
- '<SYSTEM32>\qwinsta.exe'