Техническая информация
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\rht.vbs AC
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\rht.vbs AC
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $BD5F26AD6BD86BAE184191A0D6CBD69183240C9341AD31850E177786BC90BC77691AE2691784276AD40D5D5C9286925D4F=@(40,36,97,61,36,97,61,87,114,105,116,101,45,72,111,115,116,32,39,124,124,42,42,124,124,42,42...
- %WINDIR%\explorer.exe
- firefox.exe
- Процесс firefox.exe, модуль nss3.dll
- %WINDIR%\syswow64\autofmt.exe
- %TEMP%\rht.vbs
- http://cd#.##scordapp.com/attachments/733818080668680222/758418742899900527/tsu.jpg
- http://cd#.##scordapp.com/attachments/733818080668680222/758418625429372978/p2.jpg
- DNS ASK cd#.##scordapp.com
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\rht.vbs AC' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $BD5F26AD6BD86BAE184191A0D6CBD69183240C9341AD31850E177786BC90BC77691AE2691784276AD40D5D5C9286925D4F=@(40,36,97,61,36,97,61,87,114,105,116,101,45,72,111,115,116,32,39,124,124,42,42,124,124,42,42...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\cmd.exe' /c sc query wcncsvc >> AC
- '%WINDIR%\syswow64\calc.exe'
- '%WINDIR%\syswow64\wlanext.exe'
- '%WINDIR%\syswow64\systray.exe'
- '%WINDIR%\syswow64\msdt.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\syswow64\calc.exe"