Техническая информация
- '<SYSTEM32>\cmd.exe' /s /c c:\\programdata\\index.hTA
- %ALLUSERSPROFILE%\index.hta
- 'el####orbernald.com':80
- http://el####orbernald.com/bdfh/D7B0tVd391GI3U6c0y3empD1Wrri78zhIsBF6REH5/61kD4MPfkFig7yG/MuhAbF/6GsenvhmnCx/YPjm2f5yNpPOInL0KKDtnDD3zDv6MOrrZMaqGCVUNWpeO/dITVeWcV6umwcOsWkT6USbmDEFRR0NFLNxo6mo...
- DNS ASK el####orbernald.com
- '<SYSTEM32>\cmd.exe' /s /c c:\\programdata\\index.hTA' (со скрытым окном)
- '%WINDIR%\syswow64\mshta.exe' "%ALLUSERSPROFILE%\index.hTA"
- '%WINDIR%\syswow64\regsvr32.exe' c:\users\public\defineDefineFunc.jpg