Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdate' = 'C:\TestSandbox\update.exe'
- [HKLM\SYSTEM\CurrentControlSet\Services\WindowsUpdate] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\WindowsUpdate] 'ImagePath' = 'C:\TestSandbox\update.exe'
- 'WindowsUpdate' C:\TestSandbox\update.exe
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-4226853953-3309226944-3078887307-1000\fb21442f9b14dc2790b00d21f0934573_8cf7b530-613e-439b-a8c5-ccfc0e745400
- DNS ASK c2.#vilcnc