Техническая информация
- %WINDIR%\temp\ahnfeltia.bat
- %WINDIR%\temp\undecenoates.vbs
- nul
- '34.##9.100.209':443
- '62.##.208.170':80
- '34.##9.100.209':443
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- ClassName: 'HTML Application Host Window Class' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' //nologo "%WINDIR%\Temp\undecenoates.vbs"
- '%WINDIR%\syswow64\cmd.exe' /c "%WINDIR%\Temp\ahnfeltia.bat" (со скрытым окном)
- '%WINDIR%\syswow64\timeout.exe' /t 1 /nobreak