Техническая информация
- '<SYSTEM32>\tasklist.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec bypass -nop -win 1 -
- %HOMEPATH%\ui.bat
- %TEMP%\tasks.log
- DNS ASK ec######nf-br.umbler.net
- '<SYSTEM32>\cmd.exe' /S /D /c" echo %mnlqoPERk% "
- '<SYSTEM32>\cmd.exe' /c powershell.exe -exec bypass -nop -win 1 -