Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run\] 'TRY720-IKR866' = '"%APPDATA%\Config\ssmng.exe"'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\] 'TRY720-IKR866' = '"%APPDATA%\Config\ssmng.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\zsjtum'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath 'C:\Users'"
- %TEMP%\trash_temp_1782431406\trash_doc_0.txt
- %TEMP%\trash_temp_1782431406\trash_doc_1.txt
- %TEMP%\trash_temp_1782431406\trash_doc_2.txt
- %TEMP%\trash_temp_1782431406\trash_doc_3.txt
- %TEMP%\trash_temp_1782431406\trash_doc_4.txt
- %TEMP%\trash_temp_1782431406\trash_doc_5.txt
- %TEMP%\trash_temp_1782431406\trash_doc_6.txt
- %TEMP%\trash_temp_1782431406\trash_doc_7.txt
- %TEMP%\trash_temp_1782431406\trash_doc_8.txt
- %TEMP%\trash_temp_1782431406\trash_doc_9.txt
- %TEMP%\trash_temp_1782431406\trash_doc_10.txt
- %TEMP%\trash_temp_1782431406\trash_doc_11.txt
- %TEMP%\trash_temp_1782431406\trash_doc_12.txt
- %TEMP%\trash_temp_1782431406\trash_doc_13.txt
- %TEMP%\trash_temp_1782431406\trash_doc_14.txt
- %LOCALAPPDATA%\zsjtum\system_cache_0.dat
- %LOCALAPPDATA%\zsjtum\system_cache_1.dat
- %LOCALAPPDATA%\zsjtum\system_cache_2.dat
- %LOCALAPPDATA%\zsjtum\system_cache_3.dat
- %LOCALAPPDATA%\zsjtum\system_cache_4.dat
- %LOCALAPPDATA%\zsjtum\cache\data_0.tmp
- %LOCALAPPDATA%\zsjtum\cache\data_1.tmp
- %LOCALAPPDATA%\zsjtum\cache\data_2.tmp
- %LOCALAPPDATA%\zsjtum\logs\data_0.tmp
- %LOCALAPPDATA%\zsjtum\logs\data_1.tmp
- %LOCALAPPDATA%\zsjtum\logs\data_2.tmp
- %LOCALAPPDATA%\zsjtum\temp\data_0.tmp
- %LOCALAPPDATA%\zsjtum\temp\data_1.tmp
- %LOCALAPPDATA%\zsjtum\temp\data_2.tmp
- %LOCALAPPDATA%\zsjtum\config\data_0.tmp
- %LOCALAPPDATA%\zsjtum\config\data_1.tmp
- %LOCALAPPDATA%\zsjtum\config\data_2.tmp
- %LOCALAPPDATA%\zsjtum\lxaz.sys
- %LOCALAPPDATA%\zsjtum\trash_1782431425\useless_0.txt
- %LOCALAPPDATA%\zsjtum\trash_1782431425\useless_1.txt
- %LOCALAPPDATA%\zsjtum\trash_1782431425\useless_2.txt
- %LOCALAPPDATA%\zsjtum\trash_1782431425\useless_3.txt
- %LOCALAPPDATA%\zsjtum\trash_1782431425\useless_4.txt
- %TEMP%\folder_hell_1782431425\level_1\sub_1\data_1.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_1\data_2.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_1\data_3.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_1\data_4.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_2\data_1.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_2\data_2.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_2\data_3.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_2\data_4.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_1\data_1.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_1\data_2.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_1\data_3.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_1\data_4.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_2\data_1.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_2\data_2.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_2\data_3.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_2\data_4.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_1\data_1.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_1\data_2.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_1\data_3.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_1\data_4.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_2\data_1.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_2\data_2.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_2\data_3.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_2\data_4.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_1\data_1.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_1\data_2.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_1\data_3.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_1\data_4.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_2\data_1.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_2\data_2.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_2\data_3.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_2\data_4.bin
- %TEMP%\sys_trash_1782431459_0.tmp
- %TEMP%\sys_trash_1782431460_1.tmp
- %TEMP%\sys_trash_1782431460_2.tmp
- %TEMP%\sys_trash_1782431460_3.tmp
- %TEMP%\sys_trash_1782431460_4.tmp
- %TEMP%\sys_trash_1782431461_5.tmp
- %TEMP%\sys_trash_1782431461_6.tmp
- %TEMP%\sys_trash_1782431461_7.tmp
- %LOCALAPPDATA%\zsjtum\service.exe
- %APPDATA%\config\ssmng.exe
- %TEMP%\ultimate_trash_1782431473\ultimate_0\file_0.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_0\file_1.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_0\file_2.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_1\file_0.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_1\file_1.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_1\file_2.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_2\file_0.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_2\file_1.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_2\file_2.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_3\file_0.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_3\file_1.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_3\file_2.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_4\file_0.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_4\file_1.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_4\file_2.ultimate
- %TEMP%\trash_temp_1782431406\trash_doc_0.txt
- %TEMP%\trash_temp_1782431406\trash_doc_1.txt
- %TEMP%\trash_temp_1782431406\trash_doc_2.txt
- %TEMP%\trash_temp_1782431406\trash_doc_3.txt
- %TEMP%\trash_temp_1782431406\trash_doc_4.txt
- %TEMP%\trash_temp_1782431406\trash_doc_5.txt
- %TEMP%\trash_temp_1782431406\trash_doc_6.txt
- %TEMP%\trash_temp_1782431406\trash_doc_7.txt
- %TEMP%\trash_temp_1782431406\trash_doc_8.txt
- %TEMP%\trash_temp_1782431406\trash_doc_9.txt
- %TEMP%\trash_temp_1782431406\trash_doc_10.txt
- %TEMP%\trash_temp_1782431406\trash_doc_11.txt
- %TEMP%\trash_temp_1782431406\trash_doc_12.txt
- %TEMP%\trash_temp_1782431406\trash_doc_13.txt
- %TEMP%\trash_temp_1782431406\trash_doc_14.txt
- %TEMP%\folder_hell_1782431425\level_1\sub_1\data_1.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_1\data_2.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_1\data_3.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_1\data_4.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_2\data_1.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_2\data_2.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_2\data_3.bin
- %TEMP%\folder_hell_1782431425\level_1\sub_2\data_4.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_1\data_1.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_1\data_2.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_1\data_3.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_1\data_4.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_2\data_1.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_2\data_2.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_2\data_3.bin
- %TEMP%\folder_hell_1782431425\level_2\sub_2\data_4.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_1\data_1.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_1\data_2.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_1\data_3.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_1\data_4.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_2\data_1.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_2\data_2.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_2\data_3.bin
- %TEMP%\folder_hell_1782431425\level_3\sub_2\data_4.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_1\data_1.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_1\data_2.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_1\data_3.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_1\data_4.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_2\data_1.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_2\data_2.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_2\data_3.bin
- %TEMP%\folder_hell_1782431425\level_4\sub_2\data_4.bin
- %TEMP%\sys_trash_1782431459_0.tmp
- %TEMP%\sys_trash_1782431460_1.tmp
- %TEMP%\sys_trash_1782431460_2.tmp
- %TEMP%\sys_trash_1782431460_3.tmp
- %TEMP%\sys_trash_1782431460_4.tmp
- %TEMP%\sys_trash_1782431461_5.tmp
- %TEMP%\sys_trash_1782431461_6.tmp
- %TEMP%\sys_trash_1782431461_7.tmp
- %TEMP%\ultimate_trash_1782431473\ultimate_0\file_0.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_0\file_1.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_0\file_2.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_1\file_0.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_1\file_1.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_1\file_2.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_2\file_0.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_2\file_1.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_2\file_2.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_3\file_0.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_3\file_1.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_3\file_2.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_4\file_0.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_4\file_1.ultimate
- %TEMP%\ultimate_trash_1782431473\ultimate_4\file_2.ultimate
- '31.##.168.180':5000
- '62.##.226.68':24039
- http://31.##.168.180:5000/gimasfd.exe via 31.##.168.180
- '62.##.226.68':24039
- '%LOCALAPPDATA%\zsjtum\service.exe'
- '%APPDATA%\config\ssmng.exe'
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\zsjtum'"
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Add-MpPreference -ExclusionPath 'C:\Users'"
- '<SYSTEM32>\cmd.exe' /c dir > nul
- '<SYSTEM32>\cmd.exe' /c echo Basura > nul
- '<SYSTEM32>\cmd.exe' /c ver > nul