Техническая информация
- $ayaksvehsagor как %temp%\gribjuic.exe
- '%WINDIR%\syswow64\cmd.exe' /C %tmp%\task.bat Вђ & UUUUUUUUc
- %TEMP%\task.bat
- %TEMP%\task (2).bat
- %TEMP%\task (2).bat
- '18#.#4.233.26':80
- '%WINDIR%\syswow64\cmd.exe' /C %tmp%\task.bat Вђ & UUUUUUUUc' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding