Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsService' = '%TEMP%\svchost77ad8eab.exe'
- %TEMP%\svchost77ad8eab.exe
- %TEMP%\grob_client.log
- %TEMP%\grob_1780248093625318000
- %TEMP%\grob_1780248093628162000
- %TEMP%\grob_1780248093639666200
- %TEMP%\grob_1780248093625318000
- %TEMP%\grob_1780248093628162000
- %TEMP%\grob_1780248093639666200
- '5.##.202.118':3001
- 'ap#.#pify.org':443
- 'ap#.#pify.org':443
- DNS ASK ap#.#pify.org
- '%TEMP%\svchost77ad8eab.exe'
- '<SYSTEM32>\cmd.exe' /c ver
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -Command "Add-Type -Path \"\"; $conn = New-Object -TypeName System.Data.SQLite.SQLiteConnection 2>$null; if ($conn -eq $null) { Write-Output \"\" } else { $conn.Close() }"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command " Get-PnpDevice -Class Camera -Status OK | Select-Object -Property FriendlyName, InstanceId | ConvertTo-Json "