Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath '%ProgramFiles(x86)%\Blue-Pond'
- %TEMP%\nsxf038.tmp\nsisdl.dll
- %ProgramFiles(x86)%\blue-pond\help.txt
- %ProgramFiles(x86)%\blue-pond\7zxa.dll
- %ProgramFiles(x86)%\blue-pond\7za.dll
- %ProgramFiles(x86)%\blue-pond\7za.exe
- %ProgramFiles(x86)%\blue-pond\winamp.7z
- %ProgramFiles(x86)%\blue-pond\help.txt
- %ProgramFiles(x86)%\blue-pond\winamp.7z
- %TEMP%\nsxf038.tmp\nsisdl.dll
- 'ch#####.amazonaws.com':80
- http://ch#####.amazonaws.com/
- DNS ASK ch#####.amazonaws.com
- '%ProgramFiles(x86)%\blue-pond\7za.exe' e -p176.100.243.133 winamp.7z
- '%ProgramFiles(x86)%\blue-pond\7za.exe' e -p176.100.243.133 winamp.7z (со скрытым окном)