Техническая информация
- $koala34567 как %temp%\merlin97.exe
- '%WINDIR%\syswow64\cmd.exe' /C %tmp%\task.bat & UUUUUUUUc
- %TEMP%\task.bat
- %TEMP%\task (2).bat
- %TEMP%\task (2).bat
- DNS ASK ch####hinenow.com
- DNS ASK rs###tria.com
- '%WINDIR%\syswow64\cmd.exe' /C %tmp%\task.bat & UUUUUUUUc' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding