Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'dene' = 'wscript.exe %HOMEPATH%\Downloads\dene.ini //e:VBScript //b'
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\Downloads\dene.ini //e:VBScript //b
- '<SYSTEM32>\ipconfig.exe' /flushdns
- %HOMEPATH%\downloads\dene.ini
- 'co###la.online':80
- http://83.##6.240.31/cache.php?in##################
- DNS ASK co###la.online
- '<SYSTEM32>\ipconfig.exe' /flushdns' (со скрытым окном)
- '<SYSTEM32>\wscript.exe' %HOMEPATH%\Downloads\dene.ini //e:VBScript //b' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /Automation -Embedding