Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'SecurityHealthService' = '%APPDATA%\Microsoft\Windows\Themes\SecurityHealthService.exe'
- <SYSTEM32>\tasks\microsoft\windows\security\securityhealthservice
- %APPDATA%\microsoft\windows\themes\securityhealthservice.exe
- %APPDATA%\microsoft\windows\themes\securityhealthservice.exe
- '15#.#20.119.236':5018
- 'ap#.#pify.org':80
- '15#.#20.119.236':5018
- DNS ASK ap#.#pify.org
- '<SYSTEM32>\schtasks.exe' /Create /F /SC ONLOGON /TN "\Microsoft\Windows\Security\SecurityHealthService" /TR "\"%APPDATA%\Microsoft\Windows\Themes\SecurityHealthService.exe\"" /RL HIGHEST (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ipconfig /all (со скрытым окном)
- '<SYSTEM32>\ipconfig.exe' /all
- '<SYSTEM32>\cmd.exe' /c powershell -NoProfile -Command "try { if ((Get-MpPreference).DisableRealtimeMonitoring -eq $false) { write-host 'ON' } else { write-host 'OFF' } } catch { write-host 'UNKNOWN' }" (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -Command "try { if ((Get-MpPreference).DisableRealtimeMonitoring -eq $false) { write-host 'ON' } else { write-host 'OFF' } } catch { write-host 'UNKNOWN' }"
- '<SYSTEM32>\cmd.exe' /c nvidia-smi --query-gpu=temperature.gpu --format=csv,noheader (со скрытым окном)