Техническая информация
- http://harshartcreation.com/microsoft.vbs как %temp%\microsoft.vbs
- %TEMP%\microsoft.vbs
- 'ha#####tcreation.com':80
- 'ha#####tcreation.com':443
- 'pk#.goog':80
- http://ha#####tcreation.com/microsoft.vbs
- http://pk#.goog/gsr1/gsr1.crt
- 'ha#####tcreation.com':443
- DNS ASK ha#####tcreation.com
- DNS ASK pk#.goog
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\microsoft.vbs"
- '%WINDIR%\syswow64\cmd.exe' "/c PoWerSHEll.exE -EX ByPASs ... (со скрытым окном)