Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'fU' = '"<SYSTEM32>\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -Command "$an2ajz=Get-Date...
- Системный антивирус (Защитник Windows)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "<Полный путь к файлу>"
- %WINDIR%\microsoft.net\framework64\v4.0.30319\regsvcs.exe
- <SYSTEM32>\rundll32.exe
- msedge.exe
- firefox.exe
- %APPDATA%\fu.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<Имя файла>.exe.log
- %TEMP%\2e454a5aab5335305ef7bd23513d144c\pw_user_ztgzduyjd_20260924_163102.html
- %APPDATA%\fu.exe
- 'ic###azip.com':80
- 'ap#.##legram.org':443
- http://ic###azip.com/
- DNS ASK ic###azip.com
- DNS ASK ap#.##legram.org
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\regsvcs.exe'
- '<SYSTEM32>\rundll32.exe' all -k --output-path "%TEMP%\2e454a5aab5335305ef7bd23513d144c"
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "<Полный путь к файлу>" (со скрытым окном)