Техническая информация
- <SYSTEM32>\wlrmdr.exe
- %TEMP%\~3e57.bat
- nul
- %APPDATA%\microsoft\speech\files\userlexicons\sp_329c1914559542d09028e9a1a5cf07d1.dat
- %TEMP%\~3e57.bat
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\~3E57.bat "<Полный путь к файлу>" (со скрытым окном)
- '%WINDIR%\syswow64\ping.exe' -n 10 127.1
- '%WINDIR%\syswow64\mshta.exe' vbscript:CreateObject("SAPI.SpVoice").Speak("╬╥╩╟╡╪╙ⁿ╡─╙─┴ΘГєВј─π╡─╝╞╦π╗В·╥╤╛ВЎ▒╗╬╥╟╓╚δ┴╦ГєГ╚τ╣√─π╧╓╘┌╣╪╗В·╗╣└┤╡├╝░ГєГ╬╥╧╚│Г·╚Г‘╥╗╧┬ГєВј╧Гє═√─π╕╧┐∞╣╪╗В·ГєВј║Гі╫╙ГєГ")(Window.close)
- '%WINDIR%\syswow64\mshta.exe' vbscript:CreateObject("SAPI.SpVoice").Speak("─π╛╣╚╗╗╣▓╗╣╪╗В·ГєВј╥В¬╬╥╟╫╫╘╢В»╩╓┬≡Гє┐")(Window.close)
- '%WINDIR%\syswow64\mshta.exe' vbscript:CreateObject("SAPI.SpVoice").Speak("▀┤└∩╣╛ααГєВј╫╠┴Вї═█└▓ГєВј╣╪╗В·ГєГ┐∞╣╪╗В·ГєГ")(Window.close)
- '%WINDIR%\syswow64\shutdown.exe' -s -t 120 -c └┤╫╘╙─┴Θ╡─╣╪╗В·├ⁿ┴ε
- '%WINDIR%\syswow64\mshta.exe' vbscript:CreateObject("SAPI.SpVoice").Speak("▀┤└∩╣╛ααГєВј╫╠┴Вї═█└▓,▀┤└∩╣╛ααГєВј╫╠┴Вї═█└▓")(Window.close)