Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c CmD < "%tmP%\aaaaaaaaaa.txt" & exit c
- %TEMP%\hgidgcleqxg.txt
- %TEMP%\dedxvsfzaqhqgpe.sct
- %TEMP%\wyprkdcpte.doc
- http://se####.n-document.biz/2018.txt
- DNS ASK se####.n-document.biz
- '%WINDIR%\syswow64\cmd.exe' /c CmD < "%tmP%\aaaaaaaaaa.txt" & exit c' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding