Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\run.hta
- C:\users\public\microsoft.ps1
- 'ia#####3.us.archive.org':443
- 'cd#.##scordapp.com':443
- 'ia#####3.us.archive.org':443
- 'cd#.##scordapp.com':443
- DNS ASK ia#####3.us.archive.org
- DNS ASK cd#.##scordapp.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass -file C:\Users\Public\Microsoft.ps1