Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath '%ProgramFiles(x86)%\Muddy-Bush'
- %TEMP%\nsfff84.tmp\nsisdl.dll
- %ProgramFiles(x86)%\muddy-bush\7zxa.dll
- %ProgramFiles(x86)%\muddy-bush\7za.dll
- %ProgramFiles(x86)%\muddy-bush\7za.exe
- %ProgramFiles(x86)%\muddy-bush\winamp.7z
- %ProgramFiles(x86)%\muddy-bush\winamp.7z
- %TEMP%\nsfff84.tmp\nsisdl.dll
- DNS ASK ch#####.amazonaws.com
- '%ProgramFiles(x86)%\muddy-bush\7za.exe' e -p winamp.7z
- '%ProgramFiles(x86)%\muddy-bush\7za.exe' e -p winamp.7z (со скрытым окном)