Техническая информация
- <SYSTEM32>\tasks\startmonitor_801
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'DoNotAllowExceptions' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- <SYSTEM32>\securityhealthservice.exe
- <SYSTEM32>\securityhealthsystray.exe
- %ALLUSERSPROFILE%\golden\run_86181434.exe
- %TEMP%\~dump.tmp
- %ALLUSERSPROFILE%\displaysessioncontainers.log
- %ALLUSERSPROFILE%\microsoft\windows security health\logs\shs-04162026-140715-7-7f-19041.1.amd64fre.vb_release.191206-1406.etl
- 'ip##pi.com':80
- '11#.#8.137.199':22011
- http://ip##pi.com/json/
- '11#.#8.137.199':22011
- DNS ASK ip##pi.com
- DNS ASK google.com
- '%ALLUSERSPROFILE%\golden\run_86181434.exe' -bypass
- '%ALLUSERSPROFILE%\golden\run_86181434.exe' -resurrection
- '%WINDIR%\explorer.exe' shell:::{8F70D59E-75FD-4AD4-9039-848BB3AA57C1} (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "%ALLUSERSPROFILE%\Golden\Run_86181434.exe -resurrection" (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "gpupdate /force" (со скрытым окном)
- '<SYSTEM32>\gpupdate.exe' /force
- '<SYSTEM32>\securityhealthservice.exe'
- '%ALLUSERSPROFILE%\golden\run_86181434.exe' -bypass (со скрытым окном)