Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\wedecoratethebestfeelingswithgreatnessofhappinesstobed.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JiggKFtTdHJJbmddJHZFUmJvU2VQcmVmRVJlbmNFKVsxLDNdKyd4Jy1qb2lOJycpKCAoKCd7Mn1ud...
- %APPDATA%\wedecoratethebestfeelingswithgreatnessofhappinesstobed.vbs
- '17#.#6.172.174':80
- http://17#.#6.172.174/300/wemadeperfectthingsforbetterplacesforme.vbs
- '34.##9.100.209':443
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JiggKFtTdHJJbmddJHZFUmJvU2VQcmVmRVJlbmNFKVsxLDNdKyd4Jy1qb2lOJycpKCAoKCd7Mn1ud... (со скрытым окном)