Техническая информация
- '<SYSTEM32>\cscript.exe' "%WINDIR%\temp\adobeacd-update.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -ExecutionPolicy bypass -noprofile -file %WINDIR%\temp\adobeacd-update.ps1
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\temp\adobeacd-update.bat
- %WINDIR%\temp\adobeacd-update.ps1
- %WINDIR%\temp\adobeacd-update.vbs
- %WINDIR%\temp\adobeacd-update.bat
- %WINDIR%\temp\adobeacd-update.ps1
- %WINDIR%\temp\adobeacd-update.bat
- %WINDIR%\temp\adobeacd-update.vbs
- %WINDIR%\temp\adobeacd-update.vbs
- %WINDIR%\temp\adobeacd-update.bat
- %WINDIR%\temp\adobeacd-update.ps1
- http://id###etnam.vn/images/ork.exe
- DNS ASK id###etnam.vn
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\temp\adobeacd-update.bat' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -ExecutionPolicy bypass -noprofile -file %WINDIR%\temp\adobeacd-update.ps1' (со скрытым окном)
- '<SYSTEM32>\ping.exe' 1.1.2.2 -n 2
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\temp\444.exe