Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "& 'C:\Users\Public\Videos\nwZ.Hta'
- '%WINDIR%\syswow64\mshta.exe' "C:\Users\Public\Videos\nwZ.Hta"
- C:\users\public\videos\nwz.hta
- 'ta####.#sbjdbddkslm.cloud':80
- DNS ASK ta####.#sbjdbddkslm.cloud
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\cmd.exe' /S /D /c" sEt/p 6CIQP="%NLLDN:xqTk=%%GMLP:PGWZY=/%" 0<nul 1>C:\Users\Public\Videos\nwZ%BYTO%ta"