Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\hbtgmfla] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\hbtgmfla] 'ImagePath' = '%WINDIR%\SysWOW64\hbtgmfla\masphdxf.exe'
- 'hbtgmfla' %WINDIR%\SysWOW64\hbtgmfla\masphdxf.exe
- [<HKLM>\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\SysWOW64\hbtgmfla' = '00000000'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\masphdxf.exe
- %TEMP%\4570.bat
- %TEMP%\masphdxf.exe в %WINDIR%\syswow64\hbtgmfla\masphdxf.exe
- 'mi##########m.mail.protection.outlook.com':25
- '11#.#21.193.242':443
- DNS ASK mi##########m.mail.protection.outlook.com
- '%WINDIR%\syswow64\hbtgmfla\masphdxf.exe'
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\hbtgmfla\' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\masphdxf.exe" %WINDIR%\SysWOW64\hbtgmfla\' (со скрытым окном)
- '%WINDIR%\syswow64\sc.exe' create hbtgmfla binPath= "%WINDIR%\SysWOW64\hbtgmfla\masphdxf.exe" type= own start= auto DisplayName= "P2P Support"' (со скрытым окном)
- '%WINDIR%\syswow64\sc.exe' description hbtgmfla "Internet Mobile Support"' (со скрытым окном)
- '%WINDIR%\syswow64\sc.exe' start hbtgmfla' (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Host-process for services of Windows" dir=in action=allow program="%WINDIR%\SysWOW64\svchost.exe" enable=yes>nul' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\4570.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C mkdir %WINDIR%\SysWOW64\hbtgmfla\
- '%WINDIR%\syswow64\cmd.exe' /C move /Y "%TEMP%\masphdxf.exe" %WINDIR%\SysWOW64\hbtgmfla\
- '%WINDIR%\syswow64\sc.exe' create hbtgmfla binPath= "%WINDIR%\SysWOW64\hbtgmfla\masphdxf.exe" type= own start= auto DisplayName= "P2P Support"
- '%WINDIR%\syswow64\sc.exe' description hbtgmfla "Internet Mobile Support"
- '%WINDIR%\syswow64\sc.exe' start hbtgmfla
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\4570.bat" "
- '%WINDIR%\syswow64\svchost.exe'