Техническая информация
- <SYSTEM32>\tasks\nigga startup
- Процесс xzrosvd.exe, модуль Amsi.dll
- Процесс xzrosvd.exe, модуль ntdll.dll
- %TEMP%\p724.exe
- %TEMP%\content\3104-5104-p724.exe-20-55-36-882.dump
- %APPDATA%\subdir\client.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\p724.exe.log
- %TEMP%\content\1192-2640-client.exe-20-55-38-904.dump
- DNS ASK un########ntrance.with.playit.plus
- '%TEMP%\p724.exe'
- '%APPDATA%\subdir\client.exe'
- '<SYSTEM32>\cmd.exe' /c start /B %TEMP%\p724.exe
- '<SYSTEM32>\schtasks.exe' /create /tn "Nigga Startup" /sc ONLOGON /tr "%APPDATA%\SubDir\Client.exe" /rl HIGHEST /f