Техническая информация
- '<SYSTEM32>\tasklist.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec bypass -nop -win 1 -
- %HOMEPATH%\oe.bat
- %TEMP%\tasks.log
- DNS ASK lo#####t-net.umbler.net
- '<SYSTEM32>\cmd.exe' /S /D /c" echo %TyWkLYW9MTbw48XP% "
- '<SYSTEM32>\cmd.exe' /c powershell.exe -exec bypass -nop -win 1 -