Техническая информация
- '%TEMP%\ebccabfbdfcab.exe' 9-0-7-0-7-7-4-8-3-0-0 JlBCRDYsLigtIC9KVTtQQj05KB0vTjxUUE9LREU8OjAgJkRCU01CQDUuOTcuIChDQj05KB0vUElPPVU8TVtBQT0xLTktIChMQUpTRVJWVUtMNmFwbG06LyZza3YnPUFLSC1URlAmQUlJKkFLRk8XLzxMQjxHQUE9ICZEKj0mKhwnQTI9JDEZLz0sOSUuIC87NDYtKhkrPDI9LSggKFBLSEBNQFRfR1JCVjo8VTUdL1BJTz1VPE1bPVJMQTQgKFBLSEBNQFRfRUFGRTYZKz1VRV9MUkU9GShBUEJfQ0RERUlHPjkYLEhPSlRYQktIU0tCUj0nIChUQTpKQ1ZPVVZVS0w2GStOSj0yFy89Uyo2HCdPVU5LSUZFWFBBREBPTTxJRkFAPlFKST0gJklMX0tOSkxGTUU0dGt1XhkrSkJUVUlOQk5AWFFLQlJfO0FSUzYrHCdFSUQ8WDYxGShFS1xEWUVBRkk8WEFGQFJZR1Q+RDZfXWRwZSAmREhXR0VLOUFfSUc9KjgtJzAmLjM5JTIsNRkoUEFKRT0oNCs4MS4sKzE5ICZESFdHRUs5QV9UQE0+PS0oLSosMjAoNSMyMy4uMi85KkdN
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81429514523.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81429514523.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81429514523.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsi2.tmp\cuyar.dll
- %TEMP%\1428844335.ebccabfbdfcab
- %TEMP%\ebccabfbdfcab.zip
- %TEMP%\1428844335.exe
- %TEMP%\nsi2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81429514523.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\1428844335.exe в %TEMP%\ebccabfbdfcab.exe