Техническая информация
- '<SYSTEM32>\at.exe' skjdjhfjshdfjioe4
- %TEMP%\ixp000.tmp\specializing
- %TEMP%\ixp000.tmp\genre
- %TEMP%\ixp000.tmp\regulated.pptx
- %TEMP%\ixp000.tmp\multimedia
- %TEMP%\ixp000.tmp\counters
- %TEMP%\ixp000.tmp\nl.pptx
- %TEMP%\ixp000.tmp\31604\math.exe
- %TEMP%\ixp000.tmp\31604\h
- %TEMP%\ixp000.tmp\31604\h
- 'cr###sa.cyou':443
- 'cr###sa.cyou':443
- DNS ASK Yw############NcsLvxWKpy.YwEgTRPThjfewCNcsLvxWKpy
- DNS ASK cr###sa.cyou
- '%TEMP%\ixp000.tmp\31604\math.exe' H
- '%TEMP%\ixp000.tmp\31604\math.exe' /AutoIt3ExecuteLine "Sleep(12460)"
- '<SYSTEM32>\cmd.exe' /c XCpEIhE & type Nl.pptx | %comspec% (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /S /D /c" type Nl.pptx "
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\findstr.exe' /V "Hampton" Genre
- '<SYSTEM32>\at.exe' skjdjhfjshdfjioe4 (со скрытым окном)