Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SoftConnectAgent' = '"%ALLUSERSPROFILE%\SoftConnect\SoftConnectAgent.exe"'
- <SYSTEM32>\tasks\softconnectwatchdog
- %ALLUSERSPROFILE%\softconnect\agent.log
- %ALLUSERSPROFILE%\softconnect\softconnectagent.exe
- %ALLUSERSPROFILE%\softconnect\watchdog.ps1
- %ALLUSERSPROFILE%\softconnect\softconnectagent.exe
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- http://18#.#82.187.151/api/agent/register
- '18#.#82.187.151':443
- DNS ASK x1.#.lencr.org
- '<SYSTEM32>\cmd.exe' /c icacls "%ALLUSERSPROFILE%\SoftConnect" /inheritance:r /grant:r "SYSTEM:(OI)(CI)F" /grant:r "Administrators:(OI)(CI)F" /grant:r "Users:(OI)(CI)RX" /T /Q
- '<SYSTEM32>\icacls.exe' "%ALLUSERSPROFILE%\SoftConnect" /inheritance:r /grant:r "SYSTEM:(OI)(CI)F" /grant:r "Administrators:(OI)(CI)F" /grant:r "Users:(OI)(CI)RX" /T /Q
- '<SYSTEM32>\schtasks.exe' /create /tn "SoftConnectWatchdog" /tr "powershell.exe -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File '%ALLUSERSPROFILE%\SoftConnect\watchdog.ps1'" /sc minute /mo 5 /f /rl highest ...