Техническая информация
- '<SYSTEM32>\certutil.exe' -decode %HOMEPATH%\N5uIJVSp.xls %HOMEPATH%\N5uIJVSp.dll
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\N5uIJVSp.dll,R1
- %HOMEPATH%\~wrd0000.tmp
- %HOMEPATH%\n5uijvsp.xls
- %HOMEPATH%\~$uijvsp.xls
- %HOMEPATH%\~wrd0004.tmp
- %HOMEPATH%\n5uijvsp.doc
- %HOMEPATH%\~$uijvsp.doc
- %HOMEPATH%\n5uijvsp.dll
- %HOMEPATH%\~$uijvsp.xls
- %HOMEPATH%\n5uijvsp.xls
- %HOMEPATH%\n5uijvsp.dll
- %HOMEPATH%\~wrd0000.tmp в %HOMEPATH%\n5uijvsp.xls
- %HOMEPATH%\~wrd0004.tmp в %HOMEPATH%\n5uijvsp.doc
- DNS ASK fa####ticvilla.xyz
- '<SYSTEM32>\regsvr32.exe' /i %APPDATA%\tzxctuaxxycw\tzxctuaxxycw.dll