Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Realtek HD Audio Universal Service' = '%APPDATA%\Microsoft\Protect\SecurityHealthSystray.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath <Полный путь к файлу>
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Set-MpPreference -DisableIntrusionPreventionSystem $true -DisableIOAVProtection $true -DisableRealtimeMonitoring $true -DisableScriptScanning $true -EnableControlledFolderAccess Disabled -Enabl...
- %APPDATA%\microsoft\protect\securityhealthsystray.exe
- nul
- %TEMP%\browsers-temp\all_cookies.txt
- <Полный путь к файлу>
- %APPDATA%\microsoft\protect\securityhealthsystray.exe
- %TEMP%\browsers-temp\all_cookies.txt
- 'di##ord.com':443
- 'di###rdapp.com':443
- 'di##ord.com':443
- 'di###rdapp.com':443
- DNS ASK di##ord.com
- DNS ASK di###rdapp.com
- '<SYSTEM32>\attrib.exe' +h +s <Полный путь к файлу> (со скрытым окном)
- '<SYSTEM32>\wbem\wmic.exe' cpu get Name (со скрытым окном)
- '<SYSTEM32>\attrib.exe' +h +s %APPDATA%\Microsoft\Protect\SecurityHealthSystray.exe
- '<SYSTEM32>\wbem\wmic.exe' os get Caption (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath <Полный путь к файлу> (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Set-MpPreference -DisableIntrusionPreventionSystem $true -DisableIOAVProtection $true -DisableRealtimeMonitoring $true -DisableScriptScanning $true -EnableControlledFolderAccess Disabled -Enabl... (со скрытым окном)