Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '8465B63F665496CC' = '%ALLUSERSPROFILE%\Client Demo\ClientDemo.exe'
- <SYSTEM32>\tasks\client demo
- %ALLUSERSPROFILE%\client demo\clientdemo.exe
- nul
- %TEMP%\log_2026-09_3440.txt
- '11#.#78.58.100':10336
- 'ch#####.amazonaws.com':443
- '12#.#5.231.32':80
- 'oc##.###tg2.amazontrust.com':80
- 'oc##.####ca1.amazontrust.com':80
- 'oc##.###01.amazontrust.com':80
- 'ip##fo.io':80
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c5##############
- http://oc##.####ca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
- http://oc##.###01.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBShdVEFnSEQ0gG5CBtzM48cPMe9XwQUgbgOY4qJEhjl%2Bjs7UJWf5uWQE4UCEAWWAncwNERJ0W5583t5Ti4%3D
- http://ip##fo.io/185.93.40.66/json
- http://11#.#78.58.100/98er24s8/r3wikf2a/103
- '11#.#78.58.100':10336
- 'ch#####.amazonaws.com':443
- DNS ASK ch#####.amazonaws.com
- DNS ASK oc##.###tg2.amazontrust.com
- DNS ASK oc##.####ca1.amazontrust.com
- DNS ASK oc##.###01.amazontrust.com
- DNS ASK ip##fo.io
- '%ALLUSERSPROFILE%\client demo\clientdemo.exe'
- '<SYSTEM32>\cmd.exe' /C timeout /t 3 /nobreak > Nul & Del /f /q "<Полный путь к файлу>"
- '<SYSTEM32>\timeout.exe' /t 3 /nobreak
- '<SYSTEM32>\conhost.exe' --headless --width 80 --height 24 --signal 0x894 --server 0x890
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\chcp.com' 65001
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDrives /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoViewOnDrive /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoWinKeys /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v EnableAltTab /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoClipboard /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoClose /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoLogoff /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v DisallowRun /f
- '<SYSTEM32>\icacls.exe' "%WINDIR%\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe" /remove:d everyone
- '<SYSTEM32>\icacls.exe' "%ProgramFiles%\Internet Explorer\iexplore.exe" /remove:d everyone