Техническая информация
- %TEMP%\content\3324-2204-wscript.exe-19-50-37-847.dump
- %TEMP%\qc0bk2r0\qc0bk2r0.0.cs
- %TEMP%\qc0bk2r0\qc0bk2r0.cmdline
- %TEMP%\qc0bk2r0\qc0bk2r0.out
- %TEMP%\qc0bk2r0\csc810e895e86fd4ce68819263bbf8527a.tmp
- %TEMP%\resa25b.tmp
- %TEMP%\qc0bk2r0\qc0bk2r0.dll
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBGAGkAawBzAGUAcgBiAGEAZAAgAEwAYQBwAGwAYQBuAGQAIABSAGUAcwBpAG4AIABIAG8AdwBmAGYAIABQAHIAaQBuAHQAZQBkAGEAYgAgAEEAcABvAGMAYQByAHAAbwB1AHMAIABLAG8AcgBmAGkAdAB6AHMAbQBhACAASwBpAHMA...' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\qc0bk2r0\qc0bk2r0.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA25B.tmp" "%TEMP%\qc0bk2r0\CSC810E895E86FD4CE68819263BBF8527A.TMP"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBGAGkAawBzAGUAcgBiAGEAZAAgAEwAYQBwAGwAYQBuAGQAIABSAGUAcwBpAG4AIABIAG8AdwBmAGYAIABQAHIAaQBuAHQAZQBkAGEAYgAgAEEAcABvAGMAYQByAHAAbwB1AHMAIABLAG8AcgBmAGkAdAB6AHMAbQBhACAASwBpAHMA...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\qc0bk2r0\qc0bk2r0.cmdline"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESA25B.tmp" "%TEMP%\qc0bk2r0\CSC810E895E86FD4CE68819263BBF8527A.TMP"