Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\MalDriver] 'ImagePath' = '%TEMP%\vulndriver.sys'
- 'MalDriver' %TEMP%\vulndriver.sys
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%TEMP%\Windows Helper.exe'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%TEMP%\Screendrive.exe'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionProcess 'Windows Helper.exe'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionProcess 'Screendrive.exe'"
- %TEMP%\vulndriver.sys
- 'gi##ub.com':443
- 'oc##.#ectigo.com':80
- 'ra#.####ubusercontent.com':443
- 'x1.#.lencr.org':80
- 'yr.#.lencr.org':80
- 'yr#.#.lencr.org':80
- 'gh###loader.xyz':443
- http://oc##.#ectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBS3DhJWomGbOJFU%2Fpy58BaOB6aMCwQUF5moBMFv5C1wqAoQPQPT6Rq4JmMCEQClnr21lnUdt%2FXAlQeWE5U8
- http://yr.#.lencr.org/
- http://yr#.#.lencr.org/127.crl
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- 'gh###loader.xyz':443
- DNS ASK gi##ub.com
- DNS ASK oc##.#ectigo.com
- DNS ASK ra#.####ubusercontent.com
- DNS ASK x1.#.lencr.org
- DNS ASK yr.#.lencr.org
- DNS ASK yr#.#.lencr.org
- DNS ASK gh###loader.xyz