Техническая информация
- %WINDIR%\syswow64\cscript.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe
- 'mn###esta1.com':80
- http://mn###esta1.com/loader/uploads/Lkces_Rererdrf.jpg
- DNS ASK mn###esta1.com
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwAwAA==' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwAwAA==
- '%WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe' purecrypter
- '%WINDIR%\syswow64\cscript.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"