Техническая информация
- [HKCU\Software\Classes\adamxtu\shell\open\command] '' = '"<Полный путь к файлу>" "%1"'
- Процесс epedmg.exe, модуль ntdll.dll
- %TEMP%\velopack.log
- %LOCALAPPDATA%\microsoft\credentials\1221f567d9299ba6fd0b518dc8347841
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'ap#.#damx.gg':443
- DNS ASK ap#.#damx.gg
- DNS ASK x1.#.lencr.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command "Get-Volume | Where-Object { $_.DriveType -eq 'Removable' } | ForEach-Object { Get-Partition -DriveLetter $_.DriveLetter | Get-Disk | Select-Object -... (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /Query /TN AdamxTweakingUtilityNotifications