Техническая информация
- <SYSTEM32>\tasks\dymleqrfbfccgdf
- %ALLUSERSPROFILE%\sihem.vbe
- %APPDATA%\dymleqrfbfccgdf.vbs
- '14#.#1.79.54':80
- http://14#.#1.79.54/2210/s
- http://14#.#1.79.54/2210/r
- http://14#.#1.79.54/2210/9tqj1l0acsTOaAUKXfDj.txt
- http://14#.#1.79.54/2210/v
- http://14#.#1.79.54/2210/file
- '<SYSTEM32>\wscript.exe' "%ALLUSERSPROFILE%\sihem.vbe"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\DyMLeQrfbFCcGDF.vbs"
- '<SYSTEM32>\taskeng.exe' {E4748EE5-FB7B-481B-A7BD-13D34FC9B192} S-1-5-21-3691498038-2086406363-2140527554-1000:bmdjpuhrle\user:Interactive:[1]
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' (со скрытым окном)
- '<SYSTEM32>\wermgr.exe' "-outproc" "1848" "1236"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\DyMLeQrfbFCcGDF.vbs" (со скрытым окном)