Техническая информация
- Процесс zillberreleyhost.exe, модуль Amsi.dll
- <SYSTEM32>\mshta.exe
- %TEMP%\9db682cf292a80be.pptx
- %ALLUSERSPROFILE%\systemdata\e4a57627c3955a84\zillberreleyhost.exe
- %ALLUSERSPROFILE%\systemdata\e4a57627c3955a84\launch.hta
- %TEMP%\tmp7ef4.tmp
- %TEMP%\tmp81b4.tmp
- %APPDATA%\microsoft\crypto\keys\9f137e8a2454471ff40ecc73572c7e7e_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %TEMP%\tmp7ef4.tmp
- %TEMP%\tmp81b4.tmp
- 'localhost':56001
- 'localhost':56002
- 'localhost':56003
- '45.##2.211.59':56001
- '45.##2.211.59':56001
- '%ALLUSERSPROFILE%\systemdata\e4a57627c3955a84\zillberreleyhost.exe'
- '%ALLUSERSPROFILE%\systemdata\e4a57627c3955a84\zillberreleyhost.exe' --monitor 1048
- '%WINDIR%\syswow64\cmd.exe' /c start "" "%TEMP%\9db682cf292a80be.pptx" (со скрытым окном)
- '<SYSTEM32>\mshta.exe' "%ALLUSERSPROFILE%\SystemData\e4a57627c3955a84\launch.hta"
- '%ProgramFiles(x86)%\microsoft office\office16\powerpnt.exe' "%TEMP%\9db682cf292a80be.pptx" /ou ""